#VU125273 Incorrect permission assignment for critical resource in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to incorrect permission assignment for critical resource in Feishu docx upload_file/upload_image handling when processing docx upload blocks. A local user can cause the application to read local files outside the workspace-only file policy to disclose sensitive information.
This issue is limited to the local assistant trust model.