PT-2026-20951 · Openclaw · Openclaw

Zpbrent

·

Published

2026-02-17

·

Updated

2026-03-07

·

CVE-2026-26321

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.14
Description The Feishu extension allowed the sendMediaFeishu function to interpret attacker-controlled mediaUrl values as local filesystem paths, enabling direct file reading. An attacker influencing tool calls, potentially through prompt injection, could exfiltrate local files by providing paths like /etc/passwd as the mediaUrl. The fix removes direct local file reads and uses hardened helpers with local-root restrictions for media loading.
Recommendations Upgrade to OpenClaw version 2026.2.14 or newer.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26321
GHSA-8JPQ-5H99-FF5R

Affected Products

Openclaw