PT-2026-23564 · Openclaw · Openclaw+1

Peng Zhou

·

Published

2026-02-14

·

Updated

2026-03-11

·

CVE-2026-29611

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.14
Description The BlueBubbles extension in OpenClaw contains a local file inclusion issue in how media paths are handled. This allows attackers to read arbitrary files from the local filesystem. The sendBlueBubblesMedia function does not validate the mediaPath parameters against an allowlist, enabling attackers to request sensitive files and exfiltrate them as media attachments. The issue occurs when processing non-HTTP media sources, where the software resolves the path to a local file and reads it directly from disk without proper validation.
Recommendations Upgrade to version 2026.2.14 or later. Configure channels.bluebubbles.mediaLocalRoots to explicit trusted directories.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-06332
CVE-2026-29611
GHSA-RWJ8-P9VQ-25GV

Affected Products

Bluebubbles
Openclaw