Path traversal in OpenClaw - #VU128845
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in the MCP tool result media processing pipeline when processing MCP tool result content containing injected MEDIA: directives or details.path values. A remote attacker can return a specially crafted tool result to disclose sensitive information.
If auto-reply is enabled, exploitation can occur without user interaction.