OpenClaw path traversal in isValidMedia() enables arbitrary file read (CVE-2026-25475)
In OpenClaw personal AI assistant versions prior to 2026.1.30, the isValidMedia() function in src/media/parse.ts accepted absolute paths, home directory paths and directory traversal sequences, letting the agent read any file on the system by outputting MEDIA:/path/to/file and exfiltrate it to the user or channel. The issue was patched in version 2026.1.30.
Disclosed 4 February 2026 · Record updated 13 September 2026
Impact
An agent could read arbitrary files on the host system and exfiltrate sensitive data to the user or channel.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-25475
