Local Roots Self-Whitelisting Vulnerability in OpenClaw Affects Arbitrary Host File Access
CVE-2026-41366
6MEDIUM
What is CVE-2026-41366?
OpenClaw versions prior to 2026.3.31 are susceptible to a local roots self-whitelisting vulnerability within the appendLocalMediaParentRoots function. This flaw allows model-initiated arbitrary read access to host files by exploiting inadequate validation of media parent directories. Malicious actors can leverage this vulnerability to extract credentials and access potentially sensitive files, posing a significant security risk.
Affected Version(s)
OpenClaw 0 < 2026.3.31
OpenClaw 2026.3.31
