Observable discrepancy in OpenClaw - CVE-2026-4040
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to observable discrepancy in tools.exec.safeBins approval flow when validating candidate file paths. A remote user can probe existing and non-existing filenames to disclose sensitive information.
Exploitation requires access to the execution surface.