HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-33581 — OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message...
Tuesday, March 31, 2026 at 03:16 PM UTC·Source: NIST NVD
Updated: Monday, April 6, 2026 at 12:17 AM UTC
Executive Summary
OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation. Remote attackers can exploit this by routing file requests through unvalidated alias parameters to access files outside the intended sandbox directory.
Analysis
OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation. Remote attackers can exploit this by routing file requests through unvalidated alias parameters to access files outside the intended sandbox directory.
CVSS Score: 6.5. Published: 2026-03-31T15:16:15.373.