OpenClaw Improper Path Validation Vulnerability in Sandbox Media Handling Allowing Arbitrary File Read

Vulnerability

A vulnerability exists in OpenClaw versions prior to 2026.2.24, where the application improperly validates paths in sandbox media handling. This flaw allows absolute paths under the host's temporary directory to bypass the active sandbox root. Attackers can exploit this vulnerability by sending malicious media references that are used to read and exfiltrate arbitrary files from the host temporary directory, using attachment delivery mechanisms.

Impact

Exploitation of this vulnerability could lead to unauthorized reading and exfiltration of files from the host's temporary directory, bypassing the sandbox's intended file access restrictions.

Reproduction

The vulnerability can be reproduced by sending media references that include absolute paths under the host's temporary directory, outside the active sandbox root. This can be done by importing 'os' from 'node:os' and using 'os.tmpdir()' to access the temporary directory. After the media reference is sent, the targeted file can be read and exfiltrated through the application's attachment delivery system.

Remediation

Users are advised to update OpenClaw to version 2026.2.24 or later, and to use OpenClaw's temp management helpers to avoid broad tmp-root regressions in messaging or channel code paths.

Added: Mar 19, 2026, 10:37 PM
Updated: Mar 19, 2026, 10:37 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.8
exploitability
7.7
remediation
0.0
relevance
4.1
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.