Openclaw · Openclaw · CVE-2026-43567
**Name of the Vulnerable Software and Affected Versions**
OpenClaw versions prior to 2026.4.10
**Description**
A path traversal issue exists in the screen record tool where the `outPath` parameter bypasses workspace-only filesystem guards. This allows an authorized tool call to write files to unintended locations on the system by specifying a path outside the intended workspace boundary.
**Recommendations**
Update to version 2026.4.10 or newer.