PT-2026-20951 · Openclaw · Openclaw
Zpbrent
·
Published
2026-02-17
·
Updated
2026-03-07
·
CVE-2026-26321
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.14
Description
The Feishu extension allowed the
sendMediaFeishu function to interpret attacker-controlled mediaUrl values as local filesystem paths, enabling direct file reading. An attacker influencing tool calls, potentially through prompt injection, could exfiltrate local files by providing paths like /etc/passwd as the mediaUrl. The fix removes direct local file reads and uses hardened helpers with local-root restrictions for media loading.Recommendations
Upgrade to OpenClaw version 2026.2.14 or newer.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw