OpenClaw QQBot Media Tags Arbitrary File Read Vulnerability

Vulnerability

A vulnerability allowing arbitrary file read has been identified in OpenClaw versions prior to 2026.4.10. This issue resides within the QQBot media handling, where attackers can craft reply texts that include media tags. These tags can reference local file paths outside the designated media storage area, leading to unauthorized disclosure of local files.

Impact

Exploitation of this vulnerability could result in unauthorized access to arbitrary local files on the host system.

Reproduction

The vulnerability can be reproduced by sending a reply that includes a media tag referencing a file outside of the allowed media storage directory. This can be done by using paths that traverse up the directory structure, such as relative paths that point to sensitive files like '/etc/passwd'.

Remediation

Users are advised to upgrade to OpenClaw version 2026.4.10 or later. The latest version available on npm, 2026.4.14, includes the necessary fix.

Added: May 5, 2026, 12:32 PM
Updated: May 5, 2026, 12:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
7.7
remediation
0.0
relevance
7.5
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.