CVE-2026-22171

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
18/03/2026
Last modified:
18/03/2026

Description

OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpolated directly into temporary file paths in extensions/feishu/src/media.ts. An attacker who can control Feishu media key values returned to the client can use traversal segments to escape os.tmpdir() and write arbitrary files within the OpenClaw process permissions.