CVE-2026-44996 Details
Description
OpenClaw before 2026.4.15 contains an arbitrary local file read vulnerability in the webchat audio embedding helper that fails to apply local media root containment checks. Attackers can influence agent or tool-produced ReplyPayload.mediaUrl parameters to resolve absolute local paths or file URLs, read audio-like files, and embed them base64-encoded into webchat responses.
A vulnerability allowing arbitrary local file reads has been identified in OpenClaw versions prior to 2026.4.15. This issue arises in the webchat audio embedding helper, which fails to enforce local media root containment checks. As a result, attackers can manipulate the 'ReplyPayload.mediaUrl' parameter to access absolute local paths or file URLs, read audio-like files, and embed them as base64-encoded data into webchat responses. The vulnerability exploits a lack of proper path traversal limitations, potentially crossing into sensitive file areas.
Users are advised to upgrade to OpenClaw version 2026.4.15 or later. The latest public release, 2026.4.21, includes the fix. Before upgrading, avoid exposing webchat sessions to untrusted content that could manipulate reply media URLs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | < 2026.4.15 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | Initial Analysis | [email protected] |
| May 11, 2026 | New CVE Received | [email protected] |