mediumCVSS 5.5Vulnerability
GHSA-vqj9-vhg4-27mg
## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-rwp6-7w3q-75fq. This link is maintained to preserve external references. ## Original Description OpenClaw before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad permissions. Local attackers on shared hosts can read sensitive configuration data by exploiting the recovery path to access the restored config file.
Properties
- ghsa_id
- GHSA-vqj9-vhg4-27mg
- severity
- medium
- summary
- Duplicate Advisory: Config recovery could restore openclaw.json with broad file permissions
- cvss_score
- 5.5
- cve_id
- GHSA-vqj9-vhg4-27mg
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-06-16T21:31:59Z
- source_url
- https://github.com/advisories/GHSA-vqj9-vhg4-27mg
- ghsa_updated
- 2026-06-18T20:18:52Z
Related Entities (4)
VULNERABLE_TO (1)
←[Software]npm/openclaw
AFFECTS (1)
→[Software]npm/openclaw
HAS_WEAKNESS (1)
→[Weakness]Incorrect Permission Assignment for Critical Resource
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph