Junglewise Threat Intelligence

CVE-2026-62211: OpenClaw credential redaction bypass in trajectory export

CVE-2026-62211 · Severity: medium · CVSS 5 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a software package used for managing data gateways and plugins, contains a security flaw in its trajectory export feature. This vulnerability allows users with low levels of trust to bypass security filters and access sensitive credentials or private data that should be protected. If exploited, an attacker could gain unauthorized access to system credentials, potentially leading to further unauthorized access to connected services.

Technical details

A credential redaction bypass vulnerability exists in OpenClaw's trajectory export mechanism (CWE-532/CWE-312). The root cause is a failure to properly sanitize or redact sensitive information when exporting trajectory data, particularly when triggered by lower-trust callers or misconfigured input paths. An attacker with local access and low privileges can exploit this by interacting with the export feature to leak credentials or sensitive data into logs or export files. Exploitation requires the feature to be enabled and reachable, and typically involves some level of user interaction. The issue is resolved in version 2026.6.1.

Affected products

  • OpenClaw OpenClaw < 2026.6.1

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-16: disclosed: NVD and VulnCheck publication

References

Related threats