CVE-2026-41389: Openclaw
Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.
OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclosing sensitive files or exposing credentials.
Affected products
- Openclaw Openclaw: from 2026.4.7, before 2026.4.15 (fixed in 2026.4.15)
Published 2026-04-20. Last modified 2026-06-17.