UNKNOWN npm
OpenClaw: Media Parsing Path Traversal Leads to Arbitrary File Read
GHSA-f6pf-4gjx-c94r · CVE-2026-32846 · GHSA-hggm-x7r9-mm7v
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
OpenClaw <= 2026.3.24 Media Parsing Path Traversal to Arbitrary File Read
Affected Packages / Versions
- Package:
openclaw(npm) - Latest published npm version:
2026.3.31 - Vulnerable version range:
<=2026.3.24 - Patched versions:
>= 2026.3.28 - First stable tag containing the fix:
v2026.3.28
Fix Commit(s)
4797bbc5b96e2cca5532e43b58915c051746fe37— 2026-03-25T13:35:16-06:00
Release Process Note
- The fix is already present in released version
2026.3.28.
Ready to move
Start Securing
Free, no credit card | First findings in minutes