LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-27522

openclaw · openclaw

Published
CVSS6.5
Severitymedium
WeaknessCWE-22
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon message actions when sandboxRoot is unset. Attackers can hydrate media from local absolute paths to read arbitrary host files accessible by the runtime user.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-27522

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-27522.