OpenClaw Cross-Channel Local File Exfiltration Vulnerability via Shared Reply MEDIA Paths

Vulnerability

A vulnerability in OpenClaw versions prior to 2026.4.8 allows for cross-channel local file exfiltration through shared reply MEDIA paths, which are improperly treated as trusted. This flaw can be exploited by crafting malicious shared reply MEDIA references that prompt another channel to access local file paths as if they were trusted, generated media.

Impact

Exploitation of this vulnerability could lead to unauthorized access and exfiltration of local file paths across different channels within the OpenClaw application.

Reproduction

To reproduce this vulnerability, create a shared reply MEDIA reference that includes a crafted local file path. When this reference is accessed in another channel, the application will treat the file path as trusted media, allowing for cross-channel file path exfiltration.

Remediation

Users can update to OpenClaw version 2026.4.8 or later to address this vulnerability.

Added: Apr 28, 2026, 8:24 PM
Updated: Apr 28, 2026, 8:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
0.0
relevance
6.9
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.