Beveiligingsadvies
CVE-2026-41366
CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations
Beschrijving
OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary host file read. Attackers can exploit improper media parent directory validation to exfiltrate credentials and access sensitive files.