OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes the real workspace path to child prompts. Attackers can exploit this by spawning child sessions from sandboxed parents to reveal host workspace location or related memory context to child models.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-6c4r-g249-wv3c | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-information-disclosure-via-sandboxed-session-spawn | Third Party Advisory |
Configurations
History
16 Jun 2026, 02:48
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| First Time |
Openclaw
Openclaw openclaw |
|
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-6c4r-g249-wv3c - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-information-disclosure-via-sandboxed-session-spawn - Third Party Advisory |
12 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-12 22:16
Updated : 2026-06-17 10:58
NVD link : CVE-2026-53826
Mitre link : CVE-2026-53826
CVE.ORG link : CVE-2026-53826
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-668
Exposure of Resource to Wrong Sphere
