CVE-2026-42424
MEDIUMOpenClaw < 2026.4.8 - Local File Exfiltration via Shared Reply MEDIA Paths
Title source: cnaDescription
OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channel local file exfiltration. Attackers can exploit this by crafting malicious shared reply MEDIA references to cause another channel to read local file paths as trusted generated media.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-qqq7-4hxc-x63c)
https://github.com/openclaw/openclaw/security/advisories/GHSA-qqq7-4hxc-x63c
Patch patch
Patch Commit
https://github.com/openclaw/openclaw/commit/d7c3210cd6f5fdfdc1beff4c9541673e814354d5
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.4.8 - Local File Exfiltration via Shared Reply MEDIA Paths
https://www.vulncheck.com/advisories/openclaw-local-file-exfiltration-via-shared-reply-media-paths
Scores
CVSS v3
5.7
EPSS
0.0018
EPSS Percentile
7.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-73
Status
published
Products (4)
npm/openclaw
0 - 2026.4.8npm
OpenClaw/OpenClaw
< 2026.4.8
openclaw/openclaw
< 2026.4.8
OpenClaw/OpenClaw
2026.4.8
Published
Apr 28, 2026
Tracked Since
Apr 29, 2026