HarborGuard / CVE
Back to search
HIGHCVE-2026-43567Published Modified CNA VulnCheck

CVE-2026-43567: OpenClaw < 2026.4.10 - Path Traversal in screen_record outPath Parameter

OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesystem guards. Attackers can exploit this by specifying an outPath outside the workspace boundary to write files to unintended locations on the system.

Metrics

CVSS v4.0
7.1
Severity
HIGH
Fixed in
2026.4.10
Affected Products
1

Fix available

2026.4.10
Patch commits
Affected packages
  • OpenClaw / OpenClaw
    < 2026.4.10 (from 0)
    Fixed in 2026.4.10
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N