CVE-2026-33572
OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript contents. Attackers with local access can read transcript files to extract sensitive information including secrets from tool output.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 8.4
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.12%
- CWE
- CWE-378
- Published
- 2026-03-29
- Last modified
- 2026-06-23
Affected products
- OpenClaw OpenClaw
- OpenClaw OpenClaw
Weakness type
Related vulnerabilities
- CVE-2026-46388 — osquery: Unprivileged users can temporarily read file carve contents
- CVE-2026-4137 — Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow
- CVE-2026-4822 — Enter Software Iperius Backup Backup Service temp file
- CVE-2026-2817 — Spring Data Geode Insecure Temporary Directory Usage
- CVE-2025-46685 — Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File...
- CVE-2025-46684 — Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File...
- CVE-2025-34352 — JumpCloud Remote Assist < 0.317.0 Arbitrary File Write/Delete via Insecure Temp Directory
- CVE-2025-7647 — Insecure Temporary File Handling in run-llama/llama_index