Fiche vulnérabilité
CVE-2026-27522 : faille moyenne openclaw openclaw (CVSS 5.5)
Description
OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon message actions when sandboxRoot is unset. Attackers can hydrate media from local absolute paths to read arbitrary host files accessible by the runtime user.
En bref
- Sévérité
- Moyenne (CVSS 5.5)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 18 mars 2026
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- openclaw openclaw