Openclaw cli: OpenClaw has Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22) (CVE-2026-35668)
Description
OpenClaw CLI versions from 2026.1.29 up to but not including 2026.3.24 contain a path traversal vulnerability that allows sandboxed agents to bypass sandbox restrictions and read arbitrary files from other agents' workspaces. This occurs because the `mediaUrl` and `fileUrl` parameter keys are not validated by the sandbox enforcement function, and the dispatch context omits necessary root path restrictions. The vulnerability is fixed in version 2026.3.24.
CVSS v3.1
Score 7.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A path traversal vulnerability (CVE-2026-35668) in OpenClaw CLI's sandbox enforcement allows sandboxed agents to escape their sandbox by exploiting unnormalized `mediaUrl` and `fileUrl` parameter keys. The function `normalizeSandboxMediaParams` only validates a limited set of keys (`media`, `path`, `filePath`), excluding `mediaUrl` and `fileUrl` which are used by multiple channel extensions. Additionally, the `handlePluginAction` function drops the `mediaLocalRoots` context, causing plugins to fall back to default media roots that include all agents' workspaces. This combination enables an agent to read arbitrary files outside its sandbox, demonstrated by a proof-of-concept exploit reading secret files from another agent's workspace. The issue is fixed in OpenClaw version 2026.3.24.
Potential Impact
An attacker controlling a sandboxed agent can read arbitrary files from other agents' workspaces by exploiting unvalidated parameters and missing sandbox root context. This leads to confidentiality breaches of sensitive files across agent sandboxes. The vulnerability does not affect integrity or availability but allows unauthorized data disclosure.
Mitigation Recommendations
This vulnerability is fixed in OpenClaw CLI version 2026.3.24. Users should upgrade to this version or later to remediate the issue. No additional mitigation is required as the patch fully addresses the sandbox bypass.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-35668
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6ac245a912601ec6a3166222
Added to database: 10/04/2026, 12:25:13 UTC
Last enriched: 10/04/2026, 12:53:12 UTC
Last updated: 10/04/2026, 16:08:37 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.