
Cloud Vulnerability DB
A community-led vulnerabilities database
openclaw created new session transcript JSONL files with overly broad default permissions in affected releases. On multi-user hosts, other local users or processes could read transcript contents, including secrets that might appear in tool output.
openclaw (npm)<= 2026.2.152026.2.172026.3.13 (not affected)Session transcript JSONL files are created under the local OpenClaw session store. In affected releases, newly created transcript files did not force user-only permissions, so transcript contents could be readable by other local users depending on the host environment and umask behavior.
New transcript files are now created with 0o600 permissions. Existing transcript permission drift is also remediated by the security audit fix flow.
Verified in code:
src/config/sessions/transcript.ts:82 writes new transcript files with mode: 0o600src/config/sessions/sessions.test.ts:303 includes regression coverage asserting 0o600095d522099653367e1b76fa5bb09d4ddf7c8a57cThis fix first shipped in 2026.2.17 and is present in the current npm release 2026.3.13.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."