CVE-2026-32061Disclosure(openclaw / openclaw)

LOWCVSS 6.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.17 contain a path traversal vulnerability in the $include directive resolution that allows reading arbitrary local files outside the config directory boundary. Attackers with config modification capabilities can exploit this by specifying absolute paths, traversal sequences, or symlinks to access sensitive files readable by the OpenClaw process user, including API keys and credentials.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-11); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-11: 2Mentions · 2026-03-15: 1Mentions · 2026-03-21: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-21: 103-1103-1503-21
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-112
Disclosure1General1
2026-03-151
Disclosure1
2026-03-211
General1
Full discourse4 posts
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-32061 just dropped OpenClaw path traversal = read any file on the box via $include This is the third OpenClaw CVE today. Someone's having a very bad Wednesday. How many more are coming? #infosec #CVE https://t.co/bi9W1giejo

    Post summary

    A new CVE-2026-32061 is disclosed, outlining an OpenClaw path traversal that permits reading arbitrary files via $include; no PoC, exploit code, or patch information is provided.

    1002059
    5 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32061 OpenClaw versions prior to 2026.2.17 contain a path traversal vulnerability in the $include directive resolution that allows reading arbitrary local files outside the… https://www.cve.org/CVERecord?id=CVE-2026-32061

    Post summary

    CVE‑2026‑32061 discloses a path traversal vulnerability in OpenClaw <2026.2.17 that can lead to arbitrary local file reads.

    10010130
    56.7K followersView on X
  • Orizon@OrizonCyber
    General

    OpenClaw devs watching their GitHub issues explode right now 💀 Path traversal in CVE-2026-32061 means every file on your server = public reading material Third vuln today. At this point just rewrite the whole thing? #infosec #CVE

    Post summary

    The tweet highlights a path traversal vulnerability (CVE-2026-32061) in OpenClaw, noting its severity but providing no proof‑of‑concept, exploit details, or patch information.

    1000035
    7 followersView on X
  • Orizon@OrizonCyber
    General

    🔗 Source: https://cvefeed.io/vuln/detail/CVE-2026-32061

    Post summary

    The content merely provides a link to a CVE detail page without additional information.

    0000041
    5 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more