CVE-2026-35668 - OpenClaw < 2026.3.24 - Sandbox Media Root Bypass via Unnormalized mediaUrl and fileUrl Parameters
CVE ID :CVE-2026-35668
Published : April 10, 2026, 5:17 p.m. | 49 minutes ago
Description :OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing s...
Related Vulnerabilities
- CVE-2026-5144: The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions HIGH
- CVE-2026-35620: OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist MEDIUM
- CVE-2026-35650: OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allo HIGH
- CVE-2026-35653: OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profi HIGH
- CVE-2026-35602: Vikunja has File Size Limit Bypass via Vikunja Import MEDIUM
Related Coverage
Threat Actors