CVE-2026-35668 - OpenClaw < 2026.3.24 - Sandbox Media Root Bypass via Unnormalized mediaUrl and fileUrl Parameters
CVE ID :CVE-2026-35668
Published : April 10, 2026, 5:17 p.m. | 49 minutes ago
Description :OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing s...
Related Vulnerabilities
- CVE-2026-35649: OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to MEDIUM
- CVE-2026-40189: goshs has a file-based ACL authorization bypass in goshs state-changing routes CRITICAL
- CVE-2026-35665: OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook han MEDIUM
- CVE-2026-32252: Chartbrew is an open-source web application that can connect directly to databases and APIs and use HIGH
- CVE-2026-40198: Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP MEDIUM
Related Coverage
Threat Actors