PT-2026-26411 · Openclaw · Openclaw

·

CVE-2026-32030

·

Publicado

2026-03-03

·

Atualizado

2026-03-20

CVSS v4.0

8.2

Alta

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.19
Description OpenClaw versions prior to 2026.2.19 contain a path traversal issue in the stageSandboxMedia function. This occurs when iMessage remote attachment fetching is enabled and the function accepts arbitrary absolute paths. An attacker who can manipulate attachment path metadata may be able to disclose files readable by the OpenClaw process on the configured remote host via SCP. The issue is triggered when a non-attachment path reaches the function, potentially staging files outside expected iMessage attachment directories. The vulnerability requires iMessage attachments to be enabled, remote attachment mode to be active, and the ability to inject or tamper with attachment path metadata.
Recommendations Upgrade to a version of OpenClaw that includes remote attachment path validation. If remote attachments are not required, disable iMessage attachment ingestion. Run OpenClaw under least privilege on the remote host.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32030
GHSA-X9CF-3W63-RPQ9

Produtos afetados

Openclaw