PT-2026-35793 · Openclaw · Openclaw

Rosayxy

·

Published

2026-04-09

·

Updated

2026-04-30

·

CVE-2026-41911

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.8
Description A filesystem policy bypass exists in the processing of docx uploads, enabling local file reads outside of workspace boundaries. This allows attackers to access files beyond the intended workspace-only filesystem policy via the 'upload file' and 'upload image' endpoints.
Recommendations Update to version 2026.4.8 or later. Restrict access to the 'upload file' and 'upload image' endpoints to minimize the risk of exploitation.

Fix

Incorrect Permission

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41911
GHSA-5FC7-F62M-8983

Affected Products

Openclaw