PT-2026-35791 · Openclaw · Openclaw

Antaisecuritylab

·

Published

2026-04-07

·

Updated

2026-04-30

·

CVE-2026-41408

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description A resource exhaustion issue exists in media downloads that bypasses core safety limits regarding file size, count, and cleanup operations. This allows attackers to exhaust disk space by downloading media files without triggering safety restrictions, resulting in an availability impact.
Recommendations Update to version 2026.3.31.

Fix

Unrestricted File Upload

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41408
GHSA-4G5X-2JFC-XM98

Affected Products

Openclaw