#VU125177 Path traversal in OpenClaw - CVE-2026-34510
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to access unintended network-hosted files as local content.
The vulnerability exists due to path traversal through Windows UNC share handling in Windows local-media handling and local-file access validation when processing remote-host file URLs or UNC-style paths. A remote attacker can supply a specially crafted file URL or UNC path to access unintended network-hosted files as local content.
This issue affects Windows-specific handling of local media paths.