Sandbox Media Normalization Bypass in OpenClaw by OpenClaw
CVE-2026-43532

4.9MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
5 May 2026

What is CVE-2026-43532?

OpenClaw versions 2026.4.7 through 2026.4.9 contain a vulnerability where the application fails to properly normalize the parameters for Discord event cover images during sandbox media processing. This flaw allows an attacker to bypass essential media normalization, potentially enabling them to inject host-local media references into channel action paths that expect normalized media. Successful exploitation can lead to unauthorized access to sensitive information and disruption of the intended media interactions.

Affected Version(s)

OpenClaw 2026.4.7 < 2026.4.10

OpenClaw 2026.4.10

References

CVSS V4

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Akiyama Mio (@Telecaster2147)
.