Sandbox Media Normalization Bypass in OpenClaw by OpenClaw
CVE-2026-43532
4.9MEDIUM
What is CVE-2026-43532?
OpenClaw versions 2026.4.7 through 2026.4.9 contain a vulnerability where the application fails to properly normalize the parameters for Discord event cover images during sandbox media processing. This flaw allows an attacker to bypass essential media normalization, potentially enabling them to inject host-local media references into channel action paths that expect normalized media. Successful exploitation can lead to unauthorized access to sensitive information and disruption of the intended media interactions.
Affected Version(s)
OpenClaw 2026.4.7 < 2026.4.10
OpenClaw 2026.4.10
