Impact
The flaw allows a sender to place the contents of a local file into an outbound emoji or sticker upload by hijacking the sender‑scoped media policy during those actions. While it does not provide arbitrary file system access or code execution, it grants the sender higher privileges within the Discord integration and can result in data exposure or unauthorized content distribution.
Affected Systems
OpenClaw’s Discord integration npm package (@openclaw/discord) before version 2026.9.3. The issue was addressed in version 2026.9.3.
Risk and Exploitability
The CVSS score of 6 indicates medium severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. An attacker must already have guild asset action permissions and must know or be able to deduce a usable local file path; the flaw cannot be used for unrestricted filesystem browsing or arbitrary code execution, limiting the potential impact to the authorized scope of the user.
OpenCVE Enrichment