Path traversal in OpenClaw - #VU126935
Published: April 23, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in the webchat audio embedding helper when processing an agent- or tool-produced ReplyPayload.mediaUrl. A remote attacker can supply a crafted absolute local path or file: URL to disclose sensitive information.
The target file must be readable by the gateway process, have an audio-like extension, and fit within the webchat audio size cap.