OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file targets that are treated as local content, bypassing intended access restrictions.
References
Configurations
History
No history.
Information
Published : 2026-04-01 16:23
Updated : 2026-06-17 10:39
NVD link : CVE-2026-34510
Mitre link : CVE-2026-34510
CVE.ORG link : CVE-2026-34510
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-41
Improper Resolution of Path Equivalence
