OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channel local file exfiltration. Attackers can exploit this by crafting malicious shared reply MEDIA references to cause another channel to read local file paths as trusted generated media.
References
Configurations
History
30 Apr 2026, 14:05
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openclaw/openclaw/commit/d7c3210cd6f5fdfdc1beff4c9541673e814354d5 - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-qqq7-4hxc-x63c - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-local-file-exfiltration-via-shared-reply-media-paths - Third Party Advisory | |
| First Time |
Openclaw openclaw
Openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
28 Apr 2026, 19:37
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-28 19:37
Updated : 2026-04-30 14:05
NVD link : CVE-2026-42424
Mitre link : CVE-2026-42424
CVE.ORG link : CVE-2026-42424
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-73
External Control of File Name or Path
