Local File Exfiltration Vulnerability in OpenClaw by OpenClaw
CVE-2026-42424
5.9MEDIUM
What is CVE-2026-42424?
OpenClaw before version 2026.4.8 improperly treats shared reply MEDIA paths as trusted, which presents a security flaw that can be exploited by attackers. By crafting malicious shared reply MEDIA references, a malicious actor can trigger another channel to perceive local file paths as trusted media. This manipulation allows unauthorized access and potential exfiltration of sensitive local file information, making it crucial for users to upgrade to a patched version to mitigate this risk.
Affected Version(s)
OpenClaw 0 < 2026.4.8
OpenClaw 2026.4.8
