Junglewise Threat Intelligence

CVE-2026-42438: OpenClaw authorization bypass in host media attachment reads

CVE-2026-42438 · Severity: medium · CVSS 4 · Published 2026-04-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an open-source library that manages content attachments and media access in channel-based deployments. A policy enforcement flaw allowed users denied read access by their sender or group policies to still retrieve local files from the host system through outbound media attachment requests, potentially exposing sensitive files that the OpenClaw process can access. The vulnerability affects deployments that rely on fine-grained sender/group policies to restrict access to sensitive file reads.

Technical details

The vulnerability is an authorization bypass (CWE-863) in OpenClaw's outbound host-media attachment read helper. The root cause is a policy enforcement mismatch: the host-media read capability was created based on global/agent-level read permissions without also checking sender and group-scoped tool policies that should deny access. An authenticated user (requester with privileges to trigger host-media attachment loading) could bypass sender/group policy restrictions intended to deny read access to certain channel participants. The attacker must have channel access and the deployment must allow global/agent-level host read or filesystem expansion while using sender/group policies to restrict specific users. The fix (OpenClaw 2026.4.10) threads sender, session, channel, and account context through media access resolution and intersects host-media read capability creation with existing group tool policies, so denied senders no longer receive the readFile capability.

Affected products

  • OpenClaw OpenClaw >= 2026.4.9 < 2026.4.10

Timeline

  • 2026-04-17: disclosed: GHSA-jhpv-5j76-m56h published
  • 2026-04-10: patched: Fixed in version 2026.4.10 by PR #64459
  • 2026-04-14: other: Additional attachment canonicalization hardening shipped in 2026.4.14

References

Related threats