Arbitrary Directory Deletion in OpenClaw's Mirror Mode
CVE-2026-41383

6.1MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-41383?

OpenClaw, prior to version 2026.4.2, is susceptible to an arbitrary directory deletion vulnerability when operating in mirror mode. This issue arises due to misconfigured paths—specifically, the remoteWorkspaceDir and remoteAgentWorkspaceDir settings—which attackers can exploit to manipulate OpenShell configurations. As a result, malicious actors may induce sync operations that inadvertently delete critical remote directory contents, enabling them to replace the data with potentially harmful uploaded workspace content.

Affected Version(s)

OpenClaw 0 < 2026.4.2

OpenClaw 2026.4.2

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jufeng123768
.