Information disclosure in OpenClaw - CVE-2026-41335
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in the gateway control interface bootstrap JSON when handling requests to the control interface. A remote attacker can request the bootstrap JSON to disclose sensitive information.
The exposed data includes the version and assistant agent id.