{"id":"CVE-2026-32846","aliases":["GHSA-f6pf-4gjx-c94r","GHSA-hggm-x7r9-mm7v"],"url":"https://o3.security/vulnerability/CVE-2026-32846","summary":"OpenClaw < 2026.3.28 Media Parsing Path Traversal to Arbitrary File Read","details":"## Summary\nOpenClaw <= 2026.3.24 Media Parsing Path Traversal to Arbitrary File Read\n\n## Affected Packages / Versions\n- Package: `openclaw` (npm)\n- Latest published npm version: `2026.3.31`\n- Vulnerable version range: `<=2026.3.24`\n- Patched versions: `>= 2026.3.28`\n- First stable tag containing the fix: `v2026.3.28`\n\n## Fix Commit(s)\n- `4797bbc5b96e2cca5532e43b58915c051746fe37` — 2026-03-25T13:35:16-06:00\n\n## Release Process Note\n- The fix is already present in released version `2026.3.28`.","published":"2026-03-26T16:36:00.657Z","modified":"2026-08-12T03:51:41.018309496Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.3.28"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/4797bbc5b96e2cca5532e43b58915c051746fe37","label":"openclaw/openclaw@4797bbc"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32846.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-f6pf-4gjx-c94r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32846"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-media-parsing-path-traversal-to-arbitrary-file-read"},{"type":"REPORT","url":"https://github.com/openclaw/openclaw/pull/54642"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/4797bbc5b96e2cca5532e43b58915c051746fe37"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:41.018309496Z"}}