PT-2026-26016 · Openclaw · Openclaw
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.24
Description
OpenClaw versions before 2026.2.24 contain a local media root bypass in the
sendAttachment and setGroupIcon message actions when sandboxRoot is not configured. This allows attackers to read arbitrary host files accessible by the runtime user by hydrating media from local absolute paths. The vulnerability occurs because of bypassed local media root checks when sandboxRoot is unset.Recommendations
Upgrade to OpenClaw version 2026.2.24 or later.
Exploit
Fix
Information Disclosure
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw