{"id":"CVE-2026-22171","aliases":["GHSA-vj3g-5px3-gr46"],"url":"https://o3.security/vulnerability/CVE-2026-22171","summary":"OpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File Naming","details":"OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpolated directly into temporary file paths in extensions/feishu/src/media.ts. An attacker who can control Feishu media key values returned to the client can use traversal segments to escape os.tmpdir() and write arbitrary files within the OpenClaw process permissions.","published":"2026-03-18T01:34:19.103Z","modified":"2026-08-12T03:51:28.595625038Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.2.19"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/c821099157a9767d4df208c6b12f214946507871","label":"openclaw/openclaw@c821099"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22171.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-vj3g-5px3-gr46"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22171"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-path-traversal-in-feishu-media-temporary-file-naming"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/c821099157a9767d4df208c6b12f214946507871"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/cdb00fe2428000e7a08f9b7848784a0049176705"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/ec232a9e2dff60f0e3d7e827a7c868db5254473f"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:28.595625038Z"}}