Executive brief
OpenClaw is an open-source platform that includes a memory management backend for handling workspace data. A vulnerability in the QMD backend allowed users with access to the memory tool to read any Markdown file within the workspace, even those they were not supposed to see. This could lead to the unauthorized disclosure of sensitive documentation or notes stored in the workspace.
Technical details
A path traversal vulnerability (CWE-22) exists in the OpenClaw QMD backend's `memory_get` function. The root cause is that the read path accepted arbitrary workspace Markdown paths as long as they were within the workspace root, failing to enforce canonical memory locations or indexed result sets. An attacker with network access and low privileges (access to the memory tool surface) could bypass intended access policies to retrieve any `*.md` file. The issue was addressed in version 2026.4.15 by implementing stricter path validation in `qmd-manager.ts`.
Affected products
- OpenClaw openclaw < 2026.4.15
Timeline
- 2026-04-15: patched: Fix included in version 2026.4.15
- 2026-04-16: disclosed
- 2026-04-17: advisory