CVE-2026-41335

OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that exposes version and assistant agent identifiers. Attackers can extract sensitive fingerprinting information from the Control UI bootstrap payload to identify system versions and agent configurations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

28 Apr 2026, 18:55

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/commit/c5c10adc022f42eb75ebb3bf364dd607738683b3 - () https://github.com/openclaw/openclaw/commit/c5c10adc022f42eb75ebb3bf364dd607738683b3 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-hr8g-2q7x-3f4w - () https://github.com/openclaw/openclaw/security/advisories/GHSA-hr8g-2q7x-3f4w - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-information-disclosure-via-control-ui-bootstrap-json - () https://www.vulncheck.com/advisories/openclaw-information-disclosure-via-control-ui-bootstrap-json - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw openclaw
Openclaw

23 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-23 22:16

Updated : 2026-04-28 18:55


NVD link : CVE-2026-41335

Mitre link : CVE-2026-41335

CVE.ORG link : CVE-2026-41335


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere