Path traversal in OpenClaw - CVE-2026-32026
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in sandbox media path resolution when processing attacker-controlled media references. A remote attacker can supply a crafted absolute path under the host temporary directory to disclose sensitive information.
This affects deployments that rely on sandboxRoot as a strict local filesystem boundary.