CVE-2026-34510: OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loaders
OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file targets that are treated as local content, bypassing intended access restrictions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.3.22
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34510?
CVE-2026-34510 is classified as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2026-34510?
To fix CVE-2026-34510, upgrade to OpenClaw version 2026.3.22 or later which addresses the path traversal issue.
What kind of attack can happen with CVE-2026-34510?
CVE-2026-34510 allows attackers to exploit a path traversal vulnerability to access unauthorized files through remote-host file URLs.
Which versions of OpenClaw are affected by CVE-2026-34510?
OpenClaw versions prior to 2026.3.22 are affected by CVE-2026-34510.
Is CVE-2026-34510 specific to any operating system?
CVE-2026-34510 specifically affects Windows due to the nature of the media loaders in OpenClaw.