CVE-2026-43533

Severity CVSS v4.0:
HIGH
Type:
CWE-23 Relative Path Traversal
Publication date:
05/05/2026
Last modified:
05/05/2026

Description

OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local files through outbound media handling.