CVE-2026-41389: OpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media Paths
OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclosing sensitive files or exposing credentials.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41389?
CVE-2026-41389 is classified as a high severity vulnerability due to its potential for arbitrary file access.
How do I fix CVE-2026-41389?
To fix CVE-2026-41389, upgrade to OpenClaw version 2026.4.15 or later to ensure local-root containment is enforced.
What impact does CVE-2026-41389 have on my system?
CVE-2026-41389 allows attackers to perform arbitrary file reads, leading to potential data exposure and security breaches.
What versions of OpenClaw are affected by CVE-2026-41389?
OpenClaw versions from 2026.4.7 up to but not including 2026.4.15 are affected by CVE-2026-41389.
Are there any mitigation steps for CVE-2026-41389?
Until a full upgrade can be performed, ensure strict access controls and monitoring to mitigate risks from CVE-2026-41389.