PT-2026-35793 · Openclaw · Openclaw
Rosayxy
·
Published
2026-04-28
·
Updated
2026-04-28
·
CVE-2026-41911
CVSS v3.1
6.5
Medium
| AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local file reads outside workspace boundaries. Attackers can exploit upload file and upload image endpoints to access files beyond the intended workspace-only filesystem policy.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw