Junglewise Threat Intelligence

CVE-2026-32030: OpenClaw path traversal in iMessage attachment handling

CVE-2026-32030 · Severity: low · CVSS 3.1 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an open-source communication platform that handles iMessage attachments. When remote attachment fetching is enabled, the stageSandboxMedia function fails to properly validate file paths, allowing an attacker who can tamper with attachment metadata to read arbitrary files from the remote host that the OpenClaw process has access to. This could result in exposure of sensitive configuration files, credentials, or other confidential data.

Technical details

This is a path traversal vulnerability (CWE-22) in the stageSandboxMedia function of OpenClaw. When iMessage remote attachment fetching is enabled (channels.imessage.remoteHost), the function accepts arbitrary absolute file paths without validation and uses SCP to copy them into local staging. An attacker who can inject or tamper with attachment path metadata in inbound iMessage data can specify paths outside the expected attachment directories on the remote host, allowing arbitrary file read access. The vulnerability requires three preconditions: iMessage attachments enabled (channels.imessage.includeAttachments=true), remote attachment mode active, and the ability to influence attachment path metadata. The fix involves implementing remote attachment path validation; patched versions are available starting with 2026.2.19.

Affected products

  • OpenClaw OpenClaw up to and including 2026.2.17

Timeline

  • 2026-03-03: disclosed
  • 2026-02-19: patched: Fix commit 1316e574 available; patched version 2026.2.19 released

References

Related threats