PT-2026-37022 · Openclaw · Openclaw

Anshumanbh

·

Published

2026-04-17

·

Updated

2026-05-05

·

CVE-2026-43567

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.10
Description A path traversal issue exists in the screen record tool where the outPath parameter bypasses workspace-only filesystem guards. This allows an authorized tool call to write files to unintended locations on the system by specifying a path outside the intended workspace boundary.
Recommendations Update to version 2026.4.10 or newer.

Fix

Missing Authorization

Path traversal

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-43567
GHSA-JF25-7968-H2H5

Affected Products

Openclaw