Executive brief
OpenClaw is an open-source platform used for managing digital canvas operations. A security flaw in the system's gateway allows an authenticated user to bypass directory restrictions and access sensitive files on the server. This could lead to the exposure of private configuration data or other internal system information, potentially compromising the security of the entire installation.
Technical details
A path traversal vulnerability (CWE-22) exists in the OpenClaw canvas gateway endpoint due to insufficient validation of user-supplied path parameters. An authenticated remote attacker can provide specially crafted input to the gateway to perform unauthorized file operations outside of the intended directory. Successful exploitation allows the attacker to read sensitive files in the context of the service account. The issue has been addressed in version 2026.2.21.
Affected products
- OpenClaw OpenClaw versions up to (excluding) 2026.2.21
Timeline
- 2026-02-20: other: Vulnerability reported to vendor
- 2026-03-30: patched: Coordinated public release of advisory and update
- 2026-04-11: disclosed: NVD publication date