CVE-2026-44996 MEDIUM

CVE-2026-44996: OpenClaw < 2026.4.15 - Arbitrary Local File Read via Webchat Audio Embedding

Vendor Openclaw
Product OpenClaw
Weakness CWE-22 · Path traversal
Published May 11, 2026
Last update May 11, 2026

CVSS base score

6.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

OpenClaw before 2026.4.15 contains an arbitrary local file read vulnerability in the webchat audio embedding helper that fails to apply local media root containment checks. Attackers can influence agent or tool-produced ReplyPayload.mediaUrl parameters to resolve absolute local paths or file URLs, read audio-like files, and embed them base64-encoded into webchat responses.

Key dates

02Disclosure timeline

May 11, 2026 CVE published
May 11, 2026 Record updated