CVE-2026-41370: Openclaw

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can bypass attachment-cache and root directory checks to access files outside intended directories.

Affected products

  • Openclaw Openclaw: before 2026.3.31 (fixed in 2026.3.31)

Published 2026-04-28. Last modified 2026-07-24.