Medium severity6.5NVD Advisory· Published Sep 26, 2026
CVE-2026-100594
CVE-2026-100594
Description
OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles. Attackers can access prompts, model messages, tool schemas, runtime events, and local path metadata from affected sessions by exploiting insufficient authorization checks.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.