Report: CVE-2026-42424 - OpenClaw < 2026.4.8 - Local File Exfiltration via Shared Reply MEDIA Paths

Report: CVE-2026-42424 - OpenClaw < 2026.4.8 - Local File Exfiltration via Shared Reply MEDIA Paths

CVE ID :CVE-2026-42424 Published : April 28, 2026, 7:37 p.m. | 1 hour, 2 minutes ago Description :OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channel local file exfiltration. Attackers can exploit this by crafting malicious shared reply MEDIA references to cause another channel to read local file paths as trusted generated media. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
April 28, 2026
Attack Vector: local