Executive brief
OpenClaw is an open-source gateway and control platform. A vulnerability in its Control Interface bootstrap configuration exposed sensitive information including system version numbers and agent identifiers, allowing attackers to fingerprint the system and identify specific configurations without authentication. This information disclosure has been patched in version 2026.3.31 and later.
Technical details
OpenClaw versions 2026.3.28 and earlier expose version and assistant agent identifiers in the Control UI bootstrap JSON payload (CWE-200). The vulnerability is an information disclosure that allows unauthenticated, network-accessible extraction of fingerprinting data through the bootstrap response. Attackers can identify system versions and agent configurations to facilitate targeted attacks. The fix, committed in c5c10ad, trims the payload to remove sensitive identifiers. Patched versions 2026.3.31 and later are available.
Affected products
- OpenClaw OpenClaw <=2026.3.28
Timeline
- 2026-03-31: disclosed
- 2026-03-31: patched: Version 2026.3.31 released
- 2026-04-24: advisory
- 2026-05-04: other: Advisory withdrawn as duplicate of GHSA-hr8g-2q7x-3f4w