highCVSS 6.2Vulnerability

GHSA-3gr8-2752-h46q

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-v8wv-jg3q-qwpq. This link is maintained to preserve external references. ### Original Description OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation. Remote attackers can exploit this by routing file requests through unvalidated alias parameters to access files outside the intended sandbox directory.

Properties

ghsa_id
GHSA-3gr8-2752-h46q
summary
Duplicate Advisory: OpenClaw's message tool media parameter bypasses tool policy filesystem isolation
severity
high
cvss_score
6.2
cve_id
GHSA-3gr8-2752-h46q
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-03-31T15:31:56Z
source_url
https://github.com/advisories/GHSA-3gr8-2752-h46q
ghsa_updated
2026-03-31T23:54:25Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph