Impact
OpenClaw versions older than 2026.8.1 allow an attacker to supply structured message attachments that contain multiple source fields. The application does not perform proper validation of the host path in these fields, enabling the attacker to conceal a path that refers to arbitrary files on the host system. When Telegram processes the attachment, the sanitized sandbox path check is bypassed and the requested file is read and transmitted back to the attacker, resulting in loss of confidentiality and potential data exfiltration.
Affected Systems
The vulnerability exists in OpenClaw before the 2026.8.1 release. Systems running OpenClaw versions 2026.8.0 and earlier are vulnerable. No other vendors or product versions are noted.
Risk and Exploitability
The CVSS score of 7.1 indicates a serious risk. EPSS is not available, so the baseline exploitation probability is unknown, but the lack of a KEV listing suggests no known active exploitation. The attack requires the attacker to inject a crafted structured attachment through Telegram, a vector that is remotely accessible and can be automated. If successful, the exploit gives the attacker read access to arbitrary files permitted by the host filesystem, which is a high impact attack on confidentiality and potentially availability if key files are modified.
OpenCVE Enrichment