Path traversal in OpenClaw - CVE-2026-41363
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in extensions/feishu/src/docx.ts when resolving upload file paths for Feishu upload_image actions. A remote user can supply a crafted upload path to disclose sensitive information.
The issue allows files outside the configured localRoots sandbox to be read through the upload path.