CVE-2026-62211

MEDIUM

OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export

Title source: cna
STIX 2.1

Description

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-j4cx-jvq7-79vm)
https://github.com/openclaw/openclaw/security/advisories/GHSA-j4cx-jvq7-79vm
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export
https://www.vulncheck.com/advisories/openclaw-credential-redaction-bypass-via-trajectory-export

Scores

CVSS v3 5.0
EPSS 0.0011
EPSS Percentile 1.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (3)
OpenClaw/OpenClaw < 2026.6.1
openclaw/openclaw < 2026.6.1
OpenClaw/OpenClaw 2026.6.1
Published Jul 17, 2026
Tracked Since Jul 17, 2026