Loading
Generated remediation guidance and an executive summary. No account required.
OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary host file read. Attackers can exploit improper media parent directory validation to exfiltrate credentials and access sensitive files.
No affected products information available.
Use CWE-732 to widen CVE-2026-41366 into its surrounding weakness, vendor, and product context.