Path traversal in OpenClaw - #VU126448
Published: April 17, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in webchat media embedding and the shared media resolver when processing crafted tool-result media references. A remote attacker can supply a crafted local or UNC-style file path to disclose sensitive information.
On affected Windows deployments, exploitation may also trigger network credential exposure through UNC or remote-host file path access.