PT-2026-35793 · Openclaw · Openclaw

Rosayxy

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-41911

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local file reads outside workspace boundaries. Attackers can exploit upload file and upload image endpoints to access files beyond the intended workspace-only filesystem policy.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-41911

Affected Products

Openclaw