
Cloud Vulnerability DB
A community-led vulnerabilities database
When iMessage remote attachment fetching is enabled (channels.imessage.remoteHost), stageSandboxMedia accepted arbitrary absolute paths and used SCP to copy them into local staging.
If a non-attachment path reaches this flow, files outside expected iMessage attachment directories on the remote host can be staged.
openclaw2026.2.17 (latest npm version as of February 19, 2026)Confidentiality impact. An attacker who can influence inbound attachment path metadata may disclose files readable by the OpenClaw process on the configured remote host.
channels.imessage.includeAttachments=true), andchannels.imessage.remoteHost configured or auto-detected), and1316e5740382926e45a42097b4bfe0aef7d63e8epatched_versions should be set to the next released npm version that includes remote attachment path validation, then the advisory can be published.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."