Path traversal in OpenClaw - CVE-2026-25475
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in src/media/parse.ts when parsing MEDIA: tokens that reference local file paths. A remote user can influence an agent to emit a crafted MEDIA: token to disclose sensitive information.
The issue is limited to files readable by the OpenClaw process.