Junglewise Threat Intelligence

CVE-2026-27522: OpenClaw attachment hydration path traversal with unset sandboxRoot

CVE-2026-27522 · Severity: medium · CVSS 4 · Published 2026-03-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a messaging library that processes message actions for sending attachments and setting group icons. When a configuration setting called sandboxRoot is unset, attackers can bypass security checks and read arbitrary files from the host system by crafting malicious message actions. This could expose sensitive data accessible to the application's runtime user.

Technical details

The vulnerability is a path traversal weakness (CWE-22) combined with information exposure (CWE-200) in the sendAttachment and setGroupIcon message actions. When sandboxRoot is unset, the attachment hydration logic fails to properly validate local file paths, allowing absolute path access outside intended restrictions. An attacker with the ability to trigger authorized message-action paths can read arbitrary files on the host system that are accessible to the runtime user. The vulnerability affects OpenClaw versions up to 2026.2.23 and is patched in version 2026.2.24 and later.

Affected products

  • OpenClaw OpenClaw ≤ 2026.2.23

Timeline

  • 2026-03-02: disclosed: Advisory published
  • 2026-02-25: patched: Fix released in openclaw 2026.2.24

References

Related threats