OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channel local file exfiltration. Attackers can exploit this by crafting malicious shared reply MEDIA references to cause another channel to read local file paths as trusted generated media.
References
Configurations
History
No history.
Information
Published : 2026-04-28 19:37
Updated : 2026-06-17 10:47
NVD link : CVE-2026-42424
Mitre link : CVE-2026-42424
CVE.ORG link : CVE-2026-42424
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-73
External Control of File Name or Path
