PT-2026-23564 · Openclaw · Openclaw+1
Peng Zhou
·
Published
2026-02-14
·
Updated
2026-03-11
·
CVE-2026-29611
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.14
Description
The BlueBubbles extension in OpenClaw contains a local file inclusion issue in how media paths are handled. This allows attackers to read arbitrary files from the local filesystem. The
sendBlueBubblesMedia function does not validate the mediaPath parameters against an allowlist, enabling attackers to request sensitive files and exfiltrate them as media attachments. The issue occurs when processing non-HTTP media sources, where the software resolves the path to a local file and reads it directly from disk without proper validation.Recommendations
Upgrade to version 2026.2.14 or later.
Configure
channels.bluebubbles.mediaLocalRoots to explicit trusted directories.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bluebubbles
Openclaw