Improper access control in OpenClaw - #VU126441
Published: April 17, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the outbound host-media attachment read helper when loading host-media attachments. A remote user can trigger host-media attachment loading to disclose sensitive information.
Only deployments that allow host read or filesystem root expansion at the global or agent level and rely on sender- or group-scoped policy to deny read for some channel participants are affected.