CVE-2026-59261: Openclaw
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.
Affected products
- Openclaw Openclaw: before 2026.5.28 (fixed in 2026.5.28)
Published 2026-07-08. Last modified 2026-07-09.