PT-2026-37017 · Openclaw · Openclaw
Akiyama Mio
·
Published
2026-04-17
·
Updated
2026-05-05
·
CVE-2026-43532
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.4.7 through 2026.4.9
Description
Failure to normalize Discord event cover image parameters in sandbox media processing allows attackers to bypass media normalization. This enables the injection of host-local media references into channel action paths that expect normalized media. The issue specifically involves the
eventCreate.image parameter.Recommendations
Update to version 2026.4.10 or newer.
Fix
Incomplete List of Disallowed Inputs
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw