CVE-2026-41408: OpenClaw < 2026.3.31 - Disk Exhaustion via Media Download Bypass
OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and cleanup operations. Attackers can exhaust disk space by downloading media files without triggering intended safety restrictions, causing availability impact.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41408?
CVE-2026-41408 has been classified as a high severity vulnerability due to its potential to lead to disk exhaustion.
How do I fix CVE-2026-41408?
To mitigate CVE-2026-41408, upgrade OpenClaw to version 2026.3.31 or later, which addresses the resource exhaustion issue.
What systems are affected by CVE-2026-41408?
CVE-2026-41408 affects OpenClaw versions prior to 2026.3.31 running on Node.js.
What type of attack does CVE-2026-41408 enable?
CVE-2026-41408 enables attackers to exploit media downloads to exhaust disk space through resource exhaustion.
Are there any known exploits for CVE-2026-41408?
As of now, there are no public disclosures of specific exploits for CVE-2026-41408, but the vulnerability itself poses a significant risk.