OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to delete remote directories by influencing remoteWorkspaceDir and remoteAgentWorkspaceDir configuration values. Attackers can manipulate these OpenShell config paths to cause mirror sync operations to delete unintended remote directory contents and replace them with uploaded workspace data.
References
Configurations
History
01 May 2026, 15:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openclaw/openclaw/commit/b21c9840c2e38f4bb338d031511b479d5f07ca25 - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-m34q-h93w-vg5x - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-arbitrary-remote-directory-deletion-via-mis-scoped-mirror-mode-paths - Third Party Advisory | |
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| First Time |
Openclaw openclaw
Openclaw |
28 Apr 2026, 19:37
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-28 19:37
Updated : 2026-06-17 10:46
NVD link : CVE-2026-41383
Mitre link : CVE-2026-41383
CVE.ORG link : CVE-2026-41383
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
