#VU125232 Improper access control in OpenClaw - CVE-2026-33581
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in src/infra/outbound/message-action-params.ts and src/infra/outbound/message-action-runner.ts when handling mediaUrl and fileUrl alias parameters. A remote user can supply crafted alias parameters to disclose sensitive information.
Exploitation requires the caller to be constrained to sandbox media roots.