Vulnerability Details CVE-2026-41389
OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclosing sensitive files or exposing credentials.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 12.3%
CVSS Severity
CVSS v3 Score 5.8
Products affected by CVE-2026-41389
-
cpe:2.3:a:openclaw:openclaw:2026.4.10
-
cpe:2.3:a:openclaw:openclaw:2026.4.11
-
cpe:2.3:a:openclaw:openclaw:2026.4.12
-
cpe:2.3:a:openclaw:openclaw:2026.4.7
-
cpe:2.3:a:openclaw:openclaw:2026.4.7-1
-
cpe:2.3:a:openclaw:openclaw:2026.4.8
-
cpe:2.3:a:openclaw:openclaw:2026.4.9