Executive brief
OpenClaw is a media processing tool used in messaging systems to handle file uploads and media requests with sandbox restrictions. A vulnerability in versions before 2026.3.24 allows attackers to bypass these sandbox protections and read arbitrary files on the system by manipulating alias parameters in media requests. This could expose sensitive local files, configuration data, or other confidential information stored on the affected server.
Technical details
This is a path traversal vulnerability (CWE-22) in OpenClaw's message tool, specifically in the message-action-params.ts and message-action-runner.ts components. The vulnerability occurs because the mediaUrl and fileUrl alias parameters are not validated against the same localRoots sandbox restrictions applied to the canonical media path handling. An authenticated attacker can route file requests through these unvalidated alias parameters to access files outside the intended sandbox directory. The fix was applied in commit 1d7cb6fc03, which normalizes and validates sandbox media parameters for both canonical and alias paths. Versions 2026.3.24 and later contain the fix.
Affected products
- OpenClaw OpenClaw < 2026.3.24
Timeline
- 2026-03-29: disclosed
- 2026-03-24: patched: Fix applied via commit 1d7cb6fc03; released in version 2026.3.24
- 2026-03-31: advisory