
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42438 is a sender policy bypass vulnerability in OpenClaw's outbound host-media attachment read helper that allows unauthorized local file disclosure. It affects OpenClaw version 2026.4.9 (npm package) and was disclosed on May 5, 2026, with a patch released in version 2026.4.10. The vulnerability was assigned a CVSS v3.1 base score of 7.7 (High) and a CVSS v4.0 base score of 4.9 (Medium) (GitHub Advisory, Feedly).
The root cause is an incorrect authorization flaw (CWE-863) in OpenClaw's outbound host-media attachment read helper, where the helper honored global or agent-level read access permissions but failed to also enforce sender-scoped (toolsBySender) and group-scoped tool policies. In channel deployments that used these policies to deny read access for less-trusted senders, a denied sender could still trigger host-media attachment loading, causing readable local files to be returned through the outbound media path. The fix (PR #64459, commit c949af9) threads sender identity fields — including sender ID, name, username, and E.164 phone number — through the outbound media access resolution path and intersects host-media read capability creation with the existing group tool policy, so that when a concrete sender/group override denies read, the hostReadFile media capability is no longer created (GitHub Advisory, GitHub Commit).
Successful exploitation allows an authenticated but access-denied sender to bypass authorization boundaries and retrieve local files readable by the OpenClaw process through the outbound media path. The impact is limited to confidentiality — there is no integrity or availability impact — but the scope is changed, meaning files outside the immediate authorization context can be disclosed to unauthorized channel participants. Deployments are only affected if they both enable host read or filesystem root expansion at the global/agent level and rely on sender or group-scoped policy to restrict access for some participants (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.027%, indicating a very low probability of exploitation in the near term. The vulnerability requires low-privilege authenticated access (a valid sender identity in the channel) and specific deployment conditions — both global host-read access enabled and sender/group policy configured to deny that sender — making opportunistic exploitation less likely. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly, GitHub Advisory).
toolsBySender or group policy to deny read access for certain senders.toolsBySender or group policy.hostReadFile media capability, the readable local file is returned through the outbound media path to the denied sender, bypassing the intended authorization boundary (GitHub Advisory, GitHub Commit).toolsBySender or group policy; unexpected file paths appearing in outbound media attachment metadata for restricted senders.Upgrade OpenClaw to version 2026.4.10 or later, which fixes the authorization bypass via PR #64459 (commit c949af9). Additional attachment canonicalization hardening was shipped in version 2026.4.14. As an interim workaround, restrict network access to OpenClaw instances to trusted users only, and consider disabling host read or filesystem root expansion at the global/agent level until the patch can be applied. Review and audit sender and group policy configurations to minimize the number of participants with any level of host-read access (GitHub Advisory, GitHub Commit).
The vulnerability was reported by researcher @Telecaster2147 and acknowledged by the OpenClaw maintainers, who published a GitHub Security Advisory (GHSA-jhpv-5j76-m56h) and released a fix promptly. Coverage has been limited to automated CVE aggregation sites and threat intelligence feeds, with no notable independent researcher commentary or significant social media discussion identified at this time (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."