CVE-2026-27522

MEDIUM

OpenClaw < 2026.2.24 - Arbitrary File Read via sendAttachment and setGroupIcon Message Actions

Title source: cna

Description

OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon message actions when sandboxRoot is unset. Attackers can hydrate media from local absolute paths to read arbitrary host files accessible by the runtime user.

Scores

CVSS v3 6.5
EPSS 0.0002
EPSS Percentile 6.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (3)
npm/openclaw 0 - 2026.2.24npm
OpenClaw/OpenClaw < 2026.2.24
openclaw/openclaw < 2026.2.24
Published Mar 18, 2026
Tracked Since Mar 18, 2026