PT-2026-35554 · Openclaw · Openclaw

·

CVE-2026-41366

·

Published

2026-04-03

·

Updated

2026-04-28

CVSS v4.0

7.2

High

VectorAV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description A local roots self-whitelisting issue exists in the appendLocalMediaParentRoots() function. This flaw allows for model-initiated arbitrary host file read due to improper validation of the media parent directory, which could enable attackers to exfiltrate credentials and access sensitive files.
Recommendations Update to version 2026.3.31 or later. As a temporary workaround, restrict access to the appendLocalMediaParentRoots() function to minimize the risk of exploitation.

Exploit

Fix

LPE

Incorrect Permission

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41366
GHSA-57GH-M6RQ-54CF

Affected Products

Openclaw