Junglewise Threat Intelligence

CVE-2026-25475: OpenClaw local file inclusion via MEDIA path

CVE-2026-25475 · Severity: low · CVSS 3.1 · Published 2026-02-04

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an agent-based automation platform that processes structured output tokens. A flaw in the path validation logic allows an agent to reference arbitrary files on the system (SSH keys, credentials, system files) via MEDIA: tokens, which are then staged and sent as attachments. An attacker who can influence agent output can exfiltrate sensitive files readable by the OpenClaw process.

Technical details

The vulnerability is a path traversal and local file inclusion (CWE-22, CWE-200) in the isValidMedia() function (src/media/parse.ts:17-27). The validator incorrectly accepts absolute paths (/etc/passwd), home directory paths (~/.ssh/id_rsa), and directory traversal sequences (../../../etc/passwd) without verifying the resolved path stays within a safe media directory. An authenticated or local attacker can craft MEDIA: tokens pointing to sensitive files; OpenClaw will stage and transmit the file contents as media attachments. The fix (PR #4930, commit 34e2425) restricts media staging to the designated OpenClaw media directory. No known public exploits exist yet, but the vulnerability requires only that an agent can be influenced to output the malicious token.

Affected products

  • OpenClaw openclaw <= 2026.1.30

Timeline

  • 2026-02-04: disclosed: GHSA-r8g4-86fx-92mq published
  • 2026-02-04: patched: Fix available in version 2026.2.1 (commit 34e2425b4d92e8aa8c3fdf11d5dc6b49d5849abb, PR #4930)

References

Related threats