PT-2026-37017 · Openclaw · Openclaw

Akiyama Mio

·

Published

2026-04-17

·

Updated

2026-05-05

·

CVE-2026-43532

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.4.7 through 2026.4.9
Description Failure to normalize Discord event cover image parameters in sandbox media processing allows attackers to bypass media normalization. This enables the injection of host-local media references into channel action paths that expect normalized media. The issue specifically involves the eventCreate.image parameter.
Recommendations Update to version 2026.4.10 or newer.

Fix

Incomplete List of Disallowed Inputs

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-43532
GHSA-C9H3-5P7R-MRJH

Affected Products

Openclaw