Junglewise Threat Intelligence

OpenClaw local file read in memory-wiki ingest

Severity: medium · CVSS 6.5 · Published 2026-07-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an automation and plugin platform. A vulnerability in its memory-wiki feature allows authorized users to read sensitive files from the local server that they should not have access to. This could lead to the exposure of private system data or configuration files, which are then imported into the wiki's memory.

Technical details

A vulnerability classified as CWE-732 (Incorrect Permission Assignment) exists in the memory-wiki ingest component of OpenClaw. An authenticated Gateway caller with 'operator.write' privileges can bypass intended ingest source restrictions to read arbitrary local file paths. This allows the attacker to import sensitive local file content into the wiki memory. The issue is reachable over the network but requires low-level authenticated privileges. The vulnerability has been addressed in version 2026.5.12.

Affected products

  • OpenClaw openclaw < 2026.5.12

Timeline

  • 2026-05-28: disclosed
  • 2026-07-02: advisory
  • 2026-05-12: patched: Version 2026.5.12 released

References

Related threats