{"id":"CVE-2026-41389","aliases":["GHSA-mr34-9552-qr95"],"url":"https://o3.security/vulnerability/CVE-2026-41389","summary":"OpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media Paths","details":"OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclosing sensitive files or exposing credentials.","published":"2026-04-20T17:48:43.704Z","modified":"2026-08-12T03:51:11.449553531Z","cvss":null,"epss":{"score":0.00264,"percentile":0.18171,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.4.15"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/1470de5d3e0970856d86cd99336bb8ada3fe87da","label":"openclaw/openclaw@1470de5"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41389.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-mr34-9552-qr95"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41389"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-arbitrary-file-read-via-unvalidated-tool-result-media-paths"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/1470de5d3e0970856d86cd99336bb8ada3fe87da"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/52ef42302ead9e183e6c8810e0a04ee4ef8ae9fc"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/6e58f1f9f54bca1fea1268ec0ee4c01a2af03dde"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:11.449553531Z"}}