LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-32030

openclaw · openclaw

Published
CVSS7.5
Severityhigh
WeaknessCWE-22
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accepts arbitrary absolute paths when iMessage remote attachment fetching is enabled. An attacker who can tamper with attachment path metadata can disclose files readable by the OpenClaw process on the configured remote host via SCP.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32030

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32030.