IA Squad
SearchPT
js · openclawHeads-up

OpenClaw: Config recovery sets broad file permissions on openclaw.json

Config recovery could restore openclaw.

19 Jun 2026Read 1 minSeverity: schedule it

What changed

Config recovery could restore openclaw.json with broad file permissions, potentially exposing local configuration to other same-host users.

Who it affects

OpenClaw users on shared hosts where the affected config recovery feature is enabled and reachable.

What to do today

Check openclaw.json permissions after recovery on shared hosts until patched.

The trail
Collected Audited Written Published