PT-2026-26411 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-03-03

·

Updated

2026-03-20

·

CVE-2026-32030

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.19
Description OpenClaw versions prior to 2026.2.19 contain a path traversal issue in the stageSandboxMedia function. This occurs when iMessage remote attachment fetching is enabled and the function accepts arbitrary absolute paths. An attacker who can manipulate attachment path metadata may be able to disclose files readable by the OpenClaw process on the configured remote host via SCP. The issue is triggered when a non-attachment path reaches the function, potentially staging files outside expected iMessage attachment directories. The vulnerability requires iMessage attachments to be enabled, remote attachment mode to be active, and the ability to inject or tamper with attachment path metadata.
Recommendations Upgrade to a version of OpenClaw that includes remote attachment path validation. If remote attachments are not required, disable iMessage attachment ingestion. Run OpenClaw under least privilege on the remote host.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-32030
GHSA-X9CF-3W63-RPQ9

Affected Products

Openclaw