Junglewise Threat Intelligence

AxonFlow OpenClaw plugin insecure file permissions in cache and credential files

Severity: low · CVSS 3.1 · Published 2026-05-06

Vendors: npm.

Executive brief

The AxonFlow OpenClaw plugin is a governance tool for managing AI agent workflows and controlling access to external tools. The plugin stored registration credentials and cache data in directories with overly permissive file permissions (0755 instead of 0700), allowing other local users on the same system to read sensitive information including hashed credentials and instance identifiers. This is a local privilege escalation issue that only affects systems where the user's home directory has conventional permissions.

Technical details

This vulnerability involves two related insecure file permission issues. First, plugin directories under ~/.config/axonflow/ and ~/.cache/axonflow/ were created with umask-derived default mode (often 0755) on first use and never re-validated, exposing registration records (containing hashed credentials and instance IDs) to other local users on systems where ~/.config/ itself is 0755. Second, the plugin loaded its try-registration.json credential file without validating that the file mode was 0600, allowing world-readable credential files to be silently accepted and used. Attack vector is local (AV:L) with low privilege requirement (PR:L), no user interaction needed. The fix validates and restores directory modes to 0700 on every plugin invocation and refuses to load credential files with modes other than 0600. Upgrade to version 2.0.0 or later to remediate.

Affected products

  • AxonFlow OpenClaw plugin 1.3.2 and below

Timeline

  • 2026-05-06: disclosed: Published on GitHub advisory database and OSV

References