Description
OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file targets that are treated as local content, bypassing intended access restrictions.
Problem types
CWE-41: Improper Resolution of Path Equivalence
Product status
Any version before 2026.3.22
2026.3.22 (semver)
Credits
RacerZ-fighting
Fushuling
References
github.com/...enclaw/security/advisories/GHSA-h3x4-hc5v-v2gm (GitHub Security Advisory (GHSA-h3x4-hc5v-v2gm))
github.com/...ommit/630f1479c44f78484dfa21bb407cbe6f171dac87 (Patch Commit #1)
github.com/...ommit/4fd7feb0fd4ec16c48ed983980dba79a09b3aaf5 (Patch Commit #2)
github.com/...ommit/93880717f1cd34feaa45e74e939b7a5256288901 (Patch Commit #3)
www.vulncheck.com/...url-acceptance-in-windows-media-loaders