OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-j4cx-jvq7-79vm | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-credential-redaction-bypass-via-trajectory-export | Third Party Advisory |
Configurations
History
20 Jul 2026, 16:59
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Openclaw
Openclaw openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-j4cx-jvq7-79vm - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-credential-redaction-bypass-via-trajectory-export - Third Party Advisory |
17 Jul 2026, 02:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-17 02:18
Updated : 2026-07-20 16:59
NVD link : CVE-2026-62211
Mitre link : CVE-2026-62211
CVE.ORG link : CVE-2026-62211
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-532
Insertion of Sensitive Information into Log File
