Description
OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary host file read. Attackers can exploit improper media parent directory validation to exfiltrate credentials and access sensitive files.
Problem types
CWE-732: Incorrect Permission Assignment for Critical Resource
Product status
Any version before 2026.3.31
2026.3.31 (semver)
Credits
tdjackey
References
github.com/...enclaw/security/advisories/GHSA-57gh-m6rq-54cf (GitHub Security Advisory (GHSA-57gh-m6rq-54cf))
github.com/...ommit/1ca4261d7e055d0be141ed79ebb1365d0fbc7364 (Patch Commit)
www.vulncheck.com/...localmediaparentroots-self-whitelisting (VulnCheck Advisory: OpenClaw < 2026.3.31 - Arbitrary Host File Read via appendLocalMediaParentRoots Self-Whitelisting)