Path traversal in OpenClaw - CVE-2026-26321
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in the sendMediaFeishu function in the Feishu extension when processing attacker-controlled mediaUrl values. A remote attacker can supply a crafted mediaUrl that is treated as a local filesystem path to disclose sensitive information.
Exploitation is possible if the attacker can influence tool calls, including via prompt injection.