#VU125274 Exposure of Resource to Wrong Sphere in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to exposure of resource to the wrong sphere in shared reply MEDIA handling when processing a crafted shared reply MEDIA reference. A remote user can supply a crafted shared reply MEDIA reference to disclose sensitive information.
The issue is limited to the product's local assistant trust model and does not assume a multi-tenant service boundary.