PT-2026-37010 · Openclaw · Openclaw
Akiyama Mio
·
Published
2026-04-17
·
Updated
2026-05-05
·
CVE-2026-42438
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.4.9 through 2026.4.9
Description
A sender policy bypass exists in the outbound host-media attachment read helper. This issue allows unauthorized local file disclosure when deployments allow host read or filesystem root expansion at the global or agent level but rely on sender or group-scoped policy to deny
read access for certain participants. Attackers with denied read access via toolsBySender or group policy can trigger host-media attachment loading to bypass authorization boundaries and retrieve readable local files through the outbound media path.Recommendations
Update to version 2026.4.10.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw