CVE-2026-41389
medium
CVSS v3
5.8
CVSS v2
—
VIR risk
5.8
Description
OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
Predictions
Exploit likelihood
68%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/security/advisories/GHSA-mr34-9552-qr95
Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/commit/6e58f1f9f54bca1fea1268ec0ee4c01a2af03dde
Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/commit/52ef42302ead9e183e6c8810e0a04ee4ef8ae9fc
Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/commit/1470de5d3e0970856d86cd99336bb8ada3fe87da
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| openclaw | openclaw | {"startIncluding":"2026.4.7","endExcluding":"2026.4.15"} | 2026.4.15 |
References
- https://github.com/openclaw/openclaw/commit/1470de5d3e0970856d86cd99336bb8ada3fe87da
- https://github.com/openclaw/openclaw/commit/52ef42302ead9e183e6c8810e0a04ee4ef8ae9fc
- https://github.com/openclaw/openclaw/commit/6e58f1f9f54bca1fea1268ec0ee4c01a2af03dde
- https://github.com/openclaw/openclaw/security/advisories/GHSA-mr34-9552-qr95
- https://www.vulncheck.com/advisories/openclaw-arbitrary-file-read-via-unvalidated-tool-result-media-paths
- https://nvd.nist.gov/vuln/detail/CVE-2026-41389
- https://github.com/openclaw/openclaw/pull/67293
- https://github.com/openclaw/openclaw/pull/67298
- https://github.com/openclaw/openclaw/pull/67303
- https://github.com/openclaw/openclaw
- https://github.com/advisories/GHSA-mr34-9552-qr95
CWEs
CWE-73
Verify integrity in audit chain (admin only). AS-IS.