CVE-2026-43567 - OpenClaw < 2026.4.10 - Path Traversal in screen_record outPath Parameter
CVE ID :CVE-2026-43567
Published : May 5, 2026, 11:25 a.m. | 51 minutes ago
Description :OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesystem guards. Attackers can exploit this by specifying an outPath outside the workspace boundary to write files to unintended locations on the system.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : May 5, 2026, 11:25 a.m. | 51 minutes ago
Description :OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesystem guards. Attackers can exploit this by specifying an outPath outside the workspace boundary to write files to unintended locations on the system.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...