Junglewise Threat Intelligence

CVE-2026-43567: OpenClaw screen_record path traversal bypass in workspace guard

CVE-2026-43567 · Severity: medium · CVSS 4 · Published 2026-04-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a Node.js-based tool orchestration framework. The screen_record action accepted file output paths without validating them against workspace boundaries, potentially allowing an attacker to write files outside the intended sandbox directory when the workspace-only filesystem guard was enabled.

Technical details

The vulnerability is a path traversal / authorization bypass (CWE-22, CWE-863) in the nodes tool's screen_record action. The screen_record function accepted an outPath parameter from the LLM and wrote binary data via fs.writeFile without validating the path against the workspace root. Additionally, the existing workspace-only filesystem guard wrapper only checked the 'path' parameter, not 'outPath', allowing the parameter to evade validation. An authorized tool invocation could specify an outPath like '/etc/foo' to write outside the workspace boundary. The fix extends the guard wrapper to accept configurable pathParamKeys (defaulting to ['path']) and applies it to the nodes tool with pathParamKeys: ['outPath'] when workspaceOnly is enabled. Patched in 2026.4.10 and later.

Affected products

  • OpenClaw openclaw < 2026.4.10

Timeline

  • 2026-04-17: disclosed
  • 2026-04-10: patched: Fix merged in PR #63551; v2026.4.10 includes the patch
  • 2026-04-17: kev added

References

Related threats