Junglewise Threat Intelligence

OpenClaw information disclosure in Gateway hello snapshots

Severity: low · CVSS 3.1 · Published 2026-04-24

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an open-source automation and orchestration platform. Before version 2026.4.2, the Gateway component exposed internal filesystem paths and deployment configuration details to non-admin authenticated users, leaking sensitive host information that should only be available to administrators. This information disclosure could aid attackers in fingerprinting target systems and planning follow-up attacks.

Technical details

OpenClaw's Gateway hello snapshots (sent on successful client connection) included configPath and stateDir metadata that should have been restricted to admin-scoped clients only. The vulnerability is an information disclosure issue (CWE-200) affecting authenticated but non-admin clients. The attack requires authentication and network access to the Gateway, but no further user interaction. Non-admin clients can recover host-specific filesystem paths and deployment details not intended for their access level, enabling host fingerprinting and facilitating chained attacks. The fix is available in version 2026.4.2 and later.

Affected products

  • OpenClaw openclaw <= 2026.4.1

Timeline

  • 2026-04-02: disclosed
  • 2026-04-24: patched: Fix included in version 2026.4.2

References

Related threats