Executive brief
OpenClaw is an AI-integrated platform that provides webchat and agent capabilities. A security flaw in the webchat audio component allows an attacker to trick the system into reading sensitive files from the host server. If exploited, an attacker could retrieve local files (such as configuration or system files) by disguising them as audio attachments in a chat response, potentially leading to the exposure of private data.
Technical details
A path traversal vulnerability (CWE-22) exists in OpenClaw's webchat audio embedding helper due to a lack of local media root containment checks. An attacker can use prompt injection or malicious tool outputs to manipulate the 'ReplyPayload.mediaUrl' parameter. This allows the resolution of absolute local paths or 'file://' URLs, causing the gateway process to read local files, base64-encode them, and embed them into webchat responses. The exploit is limited to files readable by the gateway process that have audio-like extensions and fall under the webchat size cap. The vulnerability is addressed in version 2026.4.15 by enforcing 'assertLocalMediaAllowed' checks and introducing a 'trustedLocalMedia' gate.
Affected products
- OpenClaw openclaw < 2026.4.15
Timeline
- 2026-04-15: patched: Fix committed to repository
- 2026-04-22: advisory: GitHub Security Advisory published
- 2026-05-11: disclosed: CVE published to NVD