<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:59:23 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-35668 — OpenClaw has Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35668</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;&amp;gt; Fixed in OpenClaw 2026.3.24, the current shipping release.&lt;/p&gt;
&lt;p&gt;### Advisory Details
**Title**: Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)&lt;/p&gt;
&lt;p&gt;**Description**:
### Summary
A path traversal vulnerability in the agent sandbox enforcement allows a sandboxed agent to read arbitrary files from other agents&amp;#39; workspaces by using the `mediaUrl` or `fileUrl` parameter key in message tool calls. The `normalizeSandboxMediaParams` function only checks `[&amp;#34;media&amp;#34;, &amp;#34;path&amp;#34;, &amp;#34;filePath&amp;#34;]` keys, while `mediaUrl` and `fileUrl` escape normalization entirely. Combined with `handlePluginAction` dropping `mediaLocalRoots` from the dispatch context, this enables a full sandbox escape where any agent can read files outside its designated sandbox root.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability exists in two files within the messaging pipeline:&lt;/p&gt;
&lt;p&gt;**1. Incomplete parameter key coverage in `normalizeSandboxMediaParams`:**&lt;/p&gt;
&lt;p&gt;In `src/infra/outbound/message-action-params.ts`, the function iterates over a hardcoded allowlist of parameter keys to validate:&lt;/p&gt;
&lt;p&gt;```typescript
// Line 212
const mediaKeys: Array&amp;lt;&amp;#34;media&amp;#34; | &amp;#34;path&amp;#34; | &amp;#34;filePath&amp;#34;&amp;gt; = [&amp;#34;media&amp;#34;, &amp;#34;path&amp;#34;, &amp;#34;filePath&amp;#34;];
```&lt;/p&gt;
&lt;p&gt;The `mediaUrl` and `fileUrl` parameter keys are not included in this array. These keys are actively used by multiple channel extensions (Discord, Telegram, Slack, Matrix, Twitch) for media attachment handling, but they completely bypass the sandbox path validation performed by `resolveSandboxedMediaSource`.&lt;/p&gt;
&lt;p&gt;**2…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;&amp;gt; Fixed in OpenClaw 2026.3.24, the current shipping release.&lt;/p&gt;
&lt;p&gt;### Advisory Details
**Title**: Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)&lt;/p&gt;
&lt;p&gt;**Description**:
### Summary
A path traversal vulnerability in the agent sandbox enforcement allows a sandboxed agent to read arbitrary files from other agents&amp;#39; workspaces by using the `mediaUrl` or `fileUrl` parameter key in message tool calls. The `normalizeSandboxMediaParams` function only checks `[&amp;#34;media&amp;#34;, &amp;#34;path&amp;#34;, &amp;#34;filePath&amp;#34;]` keys, while `mediaUrl` and `fileUrl` escape normalization entirely. Combined with `handlePluginAction` dropping `mediaLocalRoots` from the dispatch context, this enables a full sandbox escape where any agent can read files outside its designated sandbox root.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability exists in two files within the messaging pipeline:&lt;/p&gt;
&lt;p&gt;**1. Incomplete parameter key coverage in `normalizeSandboxMediaParams`:**&lt;/p&gt;
&lt;p&gt;In `src/infra/outbound/message-action-params.ts`, the function iterates over a hardcoded allowlist of parameter keys to validate:&lt;/p&gt;
&lt;p&gt;```typescript
// Line 212
const mediaKeys: Array&amp;lt;&amp;#34;media&amp;#34; | &amp;#34;path&amp;#34; | &amp;#34;filePath&amp;#34;&amp;gt; = [&amp;#34;media&amp;#34;, &amp;#34;path&amp;#34;, &amp;#34;filePath&amp;#34;];
```&lt;/p&gt;
&lt;p&gt;The `mediaUrl` and `fileUrl` parameter keys are not included in this array. These keys are actively used by multiple channel extensions (Discord, Telegram, Slack, Matrix, Twitch) for media attachment handling, but they completely bypass the sandbox path validation performed by `resolveSandboxedMediaSource`.&lt;/p&gt;
&lt;p&gt;**2…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35668</guid>
    </item>
    <item>
      <title>EUVD-2026-329545</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329545</link>
      <description>EUVD-2026-329545</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329545</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35668</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35668</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to read arbitrary files from other agents&amp;#39; workspaces via unnormalized mediaUrl or fileUrl parameter keys. Attackers can exploit incomplete parameter validation in normalizeSandboxMediaParams and missing mediaLocalRoots context to access sensitive files including API keys and configuration data outside designated sandbox roots.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to read arbitrary files from other agents&amp;#39; workspaces via unnormalized mediaUrl or fileUrl parameter keys. Attackers can exploit incomplete parameter validation in normalizeSandboxMediaParams and missing mediaLocalRoots context to access sensitive files including API keys and configuration data outside designated sandbox roots.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35668</guid>
    </item>
    <item>
      <title>GHSA-hr5v-j9h9-xjhg — OpenClaw has Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hr5v-j9h9-xjhg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;&amp;gt; Fixed in OpenClaw 2026.3.24, the current shipping release.&lt;/p&gt;
&lt;p&gt;### Advisory Details
**Title**: Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)&lt;/p&gt;
&lt;p&gt;**Description**:
### Summary
A path traversal vulnerability in the agent sandbox enforcement allows a sandboxed agent to read arbitrary files from other agents&amp;#39; workspaces by using the `mediaUrl` or `fileUrl` parameter key in message tool calls. The `normalizeSandboxMediaParams` function only checks `[&amp;#34;media&amp;#34;, &amp;#34;path&amp;#34;, &amp;#34;filePath&amp;#34;]` keys, while `mediaUrl` and `fileUrl` escape normalization entirely. Combined with `handlePluginAction` dropping `mediaLocalRoots` from the dispatch context, this enables a full sandbox escape where any agent can read files outside its designated sandbox root.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability exists in two files within the messaging pipeline:&lt;/p&gt;
&lt;p&gt;**1. Incomplete parameter key coverage in `normalizeSandboxMediaParams`:**&lt;/p&gt;
&lt;p&gt;In `src/infra/outbound/message-action-params.ts`, the function iterates over a hardcoded allowlist of parameter keys to validate:&lt;/p&gt;
&lt;p&gt;```typescript
// Line 212
const mediaKeys: Array&amp;lt;&amp;#34;media&amp;#34; | &amp;#34;path&amp;#34; | &amp;#34;filePath&amp;#34;&amp;gt; = [&amp;#34;media&amp;#34;, &amp;#34;path&amp;#34;, &amp;#34;filePath&amp;#34;];
```&lt;/p&gt;
&lt;p&gt;The `mediaUrl` and `fileUrl` parameter keys are not included in this array. These keys are actively used by multiple channel extensions (Discord, Telegram, Slack, Matrix, Twitch) for media attachment handling, but they completely bypass the sandbox path validation performed by `resolveSandboxedMediaSource`.&lt;/p&gt;
&lt;p&gt;**2…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;&amp;gt; Fixed in OpenClaw 2026.3.24, the current shipping release.&lt;/p&gt;
&lt;p&gt;### Advisory Details
**Title**: Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)&lt;/p&gt;
&lt;p&gt;**Description**:
### Summary
A path traversal vulnerability in the agent sandbox enforcement allows a sandboxed agent to read arbitrary files from other agents&amp;#39; workspaces by using the `mediaUrl` or `fileUrl` parameter key in message tool calls. The `normalizeSandboxMediaParams` function only checks `[&amp;#34;media&amp;#34;, &amp;#34;path&amp;#34;, &amp;#34;filePath&amp;#34;]` keys, while `mediaUrl` and `fileUrl` escape normalization entirely. Combined with `handlePluginAction` dropping `mediaLocalRoots` from the dispatch context, this enables a full sandbox escape where any agent can read files outside its designated sandbox root.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability exists in two files within the messaging pipeline:&lt;/p&gt;
&lt;p&gt;**1. Incomplete parameter key coverage in `normalizeSandboxMediaParams`:**&lt;/p&gt;
&lt;p&gt;In `src/infra/outbound/message-action-params.ts`, the function iterates over a hardcoded allowlist of parameter keys to validate:&lt;/p&gt;
&lt;p&gt;```typescript
// Line 212
const mediaKeys: Array&amp;lt;&amp;#34;media&amp;#34; | &amp;#34;path&amp;#34; | &amp;#34;filePath&amp;#34;&amp;gt; = [&amp;#34;media&amp;#34;, &amp;#34;path&amp;#34;, &amp;#34;filePath&amp;#34;];
```&lt;/p&gt;
&lt;p&gt;The `mediaUrl` and `fileUrl` parameter keys are not included in this array. These keys are actively used by multiple channel extensions (Discord, Telegram, Slack, Matrix, Twitch) for media attachment handling, but they completely bypass the sandbox path validation performed by `resolveSandboxedMediaSource`.&lt;/p&gt;
&lt;p&gt;**2…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hr5v-j9h9-xjhg</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1065 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1065</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1065</guid>
    </item>
  </channel>
</rss>
