


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to delete remote directories by influencing…
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 20:08:59
Source:
nvd.nist.gov
Enterprise Applications
CVE-2026-41383 affects OpenClaw versions before 2026.4.2, containing an arbitrary directory deletion vulnerability in mirror mode. Attackers can manipulate remoteWorkspaceDir and remoteAgentWorkspaceDir configuration values to delete remote directories. The vulnerability allows attackers to influence OpenShell config paths, causing mirror sync operations to delete unintended remote directory contents. The deleted directories are then replaced with uploaded workspace data controlled by the attacker. This represents a significant security risk allowing unauthorized remote file system manipulation.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41383
https://github.com/openclaw/openclaw/commit/b21c9840c2e38f4bb338d031511b479d5f07ca25
https://github.com/openclaw/openclaw/security/advisories/GHSA-m34q-h93w-vg5x
https://www.vulncheck.com/advisories/openclaw-arbitrary-remote-directory-deletion-via-mis-scoped-mirror-mode-paths
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
