Information Disclosure in OpenClaw Gateway Connect for OpenClaw Product
CVE-2026-41339
5.3MEDIUM
What is CVE-2026-41339?
OpenClaw versions prior to 2026.4.2 reveal sensitive metadata, specifically configPath and stateDir information, in Gateway connect success snapshots accessible to non-admin authenticated users. This exposure allows unauthorized clients to glean host-specific filesystem paths and deployment details, which can lead to host fingerprinting and potentially facilitate further chained attacks against the system.
Affected Version(s)
OpenClaw 0 < 2026.4.2
OpenClaw 2026.4.2
