Ad

CVE-2026-25475

MEDIUM CVSS 3.1: 6.5 EPSS 0.11%
Updated Feb 05, 2026
OpenClaw
Parameter Value
CVSS 6.5 (MEDIUM)
Fixed In 2026.1.30
Type CWE-200 (Information Exposure), CWE-22 (Path Traversal)
Vendor OpenClaw
Public PoC No

OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute paths, home directory paths, and directory traversal sequences. An agent can read any file on the system by outputting MEDIA:/path/to/file, exfiltrating sensitive data to the user/channel.

This issue has been patched in version 2026.1.30.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1