Executive brief
OpenClaw is an AI assistant application that processes user-controlled documents. The Feishu docx file upload feature could read local files outside the designated workspace directory, bypassing intended file access restrictions. An attacker with local access could exploit document processing to access sensitive files on the system that should have been restricted.
Technical details
The vulnerability is a permission assignment issue (CWE-732) in OpenClaw's document upload processing. When handling Feishu docx files containing upload_file or upload_image blocks, the application failed to properly enforce workspace-only file access restrictions, allowing reads of local files outside the intended security boundary. This represents an incomplete fix to a prior advisory (GHSA-qf48-qfv4-jjm9). The attack requires local access to the system and user interaction to upload a specially crafted docx file. An attacker could read arbitrary local files by embedding malicious upload blocks in a docx document. The vulnerability was fixed in commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5 and is available in npm version 2026.4.8 and later.
Affected products
- OpenClaw openclaw <=2026.4.3
Timeline
- 2026-04-09: disclosed
- 2026-04-08: patched: Patched in version 2026.4.8