Junglewise Threat Intelligence

CVE-2026-43532: OpenClaw sandbox media normalization bypass in Discord event cover images

CVE-2026-43532 · Severity: low · CVSS 3.1 · Published 2026-04-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a Node.js library used by Discord applications to manage events and media handling. A vulnerability in versions 2026.4.7 through 2026.4.9 allows Discord event cover images to bypass sandbox media normalization controls, potentially exposing host-local media references that should have been restricted. This could allow unauthorized access to local media files through Discord event creation.

Technical details

This vulnerability is a path traversal / sandbox bypass (CWE-22, CWE-184) in the OpenClaw library's media normalization for Discord event cover images. The vulnerability exists in the eventCreate.image parameter, which was not properly validated through the sandbox media normalization path applied to other local media. Attackers with the ability to create Discord events could craft malicious image parameters to reference host-local files, bypassing the normalization controls. The fix, released in version 2026.4.10 and included in 2026.4.14, adds eventCreate.image to the sandbox media normalization process and extends coverage to the event-create media path. Users should upgrade to 2026.4.10 or later.

Affected products

  • OpenClaw OpenClaw >= 2026.4.7, < 2026.4.10

Timeline

  • 2026-04-17: disclosed
  • 2026-04-17: patched: Fix released in version 2026.4.10

References

Related threats