Path traversal in OpenClaw - CVE-2026-32061
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in config $include resolution when processing user-controlled include paths in configuration files. A remote user can specify absolute or traversal paths to disclose sensitive information.
The impact is limited to files readable by the OpenClaw process user.