PT-2026-37018 · Openclaw · Openclaw
Feiyang666
·
Published
2026-04-17
·
Updated
2026-05-06
·
CVE-2026-43533
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.10
Description
An arbitrary file read issue exists in QQBot media tags. Attackers can craft malicious reply text containing media tags to reference host-local paths outside the intended media storage boundary, leading to the disclosure of arbitrary local files through outbound media handling.
Recommendations
Update to version 2026.4.10 or newer.
Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw