Junglewise Threat Intelligence

CVE-2026-53825: OpenClaw arbitrary file read in memory-wiki ingest

CVE-2026-53825 · Severity: medium · CVSS 6.5 · Published 2026-06-12

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a platform for managing gateway operations and plugins, contains a security flaw in its memory-wiki ingest feature. An authorized user with basic write permissions can exploit this to read sensitive files from the underlying server that they should not have access to. This could lead to the exposure of configuration files, credentials, or other private system data, potentially allowing for further unauthorized access.

Technical details

A path traversal vulnerability (CWE-22/CWE-732) exists in the memory-wiki ingest component of OpenClaw. The root cause is improper limitation of pathname input, allowing an authenticated attacker with 'operator.write' scope to specify arbitrary local file paths. By doing so, the attacker can import the contents of sensitive system files into the wiki memory, effectively bypassing intended access restrictions. This is reachable over the network but requires valid operator credentials. The issue is resolved in version 2026.4.7.

Affected products

  • OpenClaw OpenClaw < 2026.4.7

Timeline

  • 2026-05-28: advisory: GitHub Security Advisory published
  • 2026-06-12: disclosed: NVD publication date

References

Related threats