Local File Exfiltration Vulnerability in OpenClaw by OpenClaw
CVE-2026-42424

5.9MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-42424?

OpenClaw before version 2026.4.8 improperly treats shared reply MEDIA paths as trusted, which presents a security flaw that can be exploited by attackers. By crafting malicious shared reply MEDIA references, a malicious actor can trigger another channel to perceive local file paths as trusted media. This manipulation allows unauthorized access and potential exfiltration of sensitive local file information, making it crucial for users to upgrade to a patched version to mitigate this risk.

Affected Version(s)

OpenClaw 0 < 2026.4.8

OpenClaw 2026.4.8

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuki Shiroi (@threalwinky)
.