Path traversal in OpenClaw - CVE-2026-27522
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in sendAttachment and setGroupIcon message actions when hydrating media from local absolute paths with sandboxRoot unset. A remote user can trigger an authorized message-action path to disclose sensitive information.
Only deployments with sandboxRoot unset are vulnerable.