CVE-2026-41370: OpenClaw < 2026.3.31 - Path Traversal via Inbound Channel Attachment Path in ACP Dispatch
OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can bypass attachment-cache and root directory checks to access files outside intended directories.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.3.31
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41370?
CVE-2026-41370 is classified as a high severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2026-41370?
To fix CVE-2026-41370, upgrade OpenClaw to version 2026.3.31 or later.
What type of vulnerability is CVE-2026-41370?
CVE-2026-41370 is a path traversal vulnerability that allows attackers to read arbitrary files.
Who is affected by CVE-2026-41370?
Any user of OpenClaw versions prior to 2026.3.31 is affected by CVE-2026-41370.
Can CVE-2026-41370 be exploited remotely?
Yes, CVE-2026-41370 can be exploited by remote attackers to access restricted files.