CVE-2026-27522
MEDIUMOpenClaw < 2026.2.24 - Arbitrary File Read via sendAttachment and setGroupIcon Message Actions
Title source: cnaDescription
OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon message actions when sandboxRoot is unset. Attackers can hydrate media from local absolute paths to read arbitrary host files accessible by the runtime user.
References (3)
Core 3
Core References
Third Party Advisory third-party-advisory
GitHub Security Advisory (GHSA-fqcm-97m6-w7rm)
https://github.com/openclaw/openclaw/security/advisories/GHSA-fqcm-97m6-w7rm
Patch patch
Patch Commit
https://github.com/openclaw/openclaw/commit/270ab03e379f9653e15f7033c9830399b66b7e51
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.2.24 - Arbitrary File Read via sendAttachment and setGroupIcon Message Actions
https://www.vulncheck.com/advisories/openclaw-arbitrary-file-read-via-sendattachment-and-setgroupicon-message-actions
Scores
CVSS v3
6.5
EPSS
0.0037
EPSS Percentile
28.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (3)
npm/openclaw
0 - 2026.2.24npm
OpenClaw/OpenClaw
< 2026.2.24
openclaw/openclaw
< 2026.2.24
Published
Mar 18, 2026
Tracked Since
Mar 18, 2026