CVE-2026-53826

OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes the real workspace path to child prompts. Attackers can exploit this by spawning child sessions from sandboxed parents to reveal host workspace location or related memory context to child models.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

16 Jun 2026, 02:48

Type Values Removed Values Added
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw
Openclaw openclaw
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-6c4r-g249-wv3c - () https://github.com/openclaw/openclaw/security/advisories/GHSA-6c4r-g249-wv3c - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-information-disclosure-via-sandboxed-session-spawn - () https://www.vulncheck.com/advisories/openclaw-information-disclosure-via-sandboxed-session-spawn - Third Party Advisory

12 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 22:16

Updated : 2026-06-17 10:58


NVD link : CVE-2026-53826

Mitre link : CVE-2026-53826

CVE.ORG link : CVE-2026-53826


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-668

Exposure of Resource to Wrong Sphere