PT-2026-28443 · Openclaw · Openclaw

Vulncheck

+1

·

Published

2026-03-26

·

Updated

2026-05-20

·

CVE-2026-32846

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions through 2026.3.23
Description The software contains a path traversal issue in media parsing. This allows attackers to read arbitrary files by bypassing path validation in the isLikelyLocalPath() and isValidMedia() functions. The incomplete validation and the allowBareFilename bypass enable attackers to reference files outside the intended application sandbox, potentially disclosing sensitive information such as system files, environment files, and SSH keys.
Recommendations Update to a version after commit 4797bbc to resolve the issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-32846
GHSA-HGGM-X7R9-MM7V

Affected Products

Openclaw