PT-2026-35793 · Openclaw · Openclaw
Rosayxy
·
Published
2026-04-09
·
Updated
2026-04-30
·
CVE-2026-41911
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.8
Description
A filesystem policy bypass exists in the processing of docx uploads, enabling local file reads outside of workspace boundaries. This allows attackers to access files beyond the intended workspace-only filesystem policy via the 'upload file' and 'upload image' endpoints.
Recommendations
Update to version 2026.4.8 or later.
Restrict access to the 'upload file' and 'upload image' endpoints to minimize the risk of exploitation.
Fix
Incorrect Permission
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw