PT-2026-37010 · Openclaw · Openclaw

Akiyama Mio

·

Published

2026-04-17

·

Updated

2026-05-05

·

CVE-2026-42438

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.4.9 through 2026.4.9
Description A sender policy bypass exists in the outbound host-media attachment read helper. This issue allows unauthorized local file disclosure when deployments allow host read or filesystem root expansion at the global or agent level but rely on sender or group-scoped policy to deny read access for certain participants. Attackers with denied read access via toolsBySender or group policy can trigger host-media attachment loading to bypass authorization boundaries and retrieve readable local files through the outbound media path.
Recommendations Update to version 2026.4.10.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-42438
GHSA-JHPV-5J76-M56H

Affected Products

Openclaw