CVE-2026-43533: Openclaw
High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.
OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local files through outbound media handling.
Affected products
- Openclaw Openclaw: before 2026.4.10 (fixed in 2026.4.10)
Published 2026-05-05. Last modified 2026-06-17.