PT-2026-26016 · Openclaw · Openclaw

Baozongwixd

·

Published

2026-03-18

·

Updated

2026-03-18

·

CVE-2026-27522

CVSS v3.1
6.5
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon message actions when sandboxRoot is unset. Attackers can hydrate media from local absolute paths to read arbitrary host files accessible by the runtime user.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-27522

Affected Products

Openclaw