#VU125165 Incorrect permission assignment for critical resource in OpenClaw - CVE-2026-33572
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to incorrect permission assignment for a critical resource in session transcript JSONL files when creating new transcript files under the local session store. A local user can read transcript files to disclose sensitive information.
On multi-user hosts, exposure depends on the host environment and umask behavior.