CVE-2026-43532

Source
https://cve.org/CVERecord?id=CVE-2026-43532
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43532.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-43532
Aliases
Published
2026-05-05T11:25:04.990Z
Modified
2026-08-12T03:51:34.226161220Z
Severity
  • 4.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
OpenClaw 2026.4.7 < 2026.4.10 - Sandbox Media Normalization Bypass via Discord Event Cover Image
Details

OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media processing. Attackers can bypass media normalization to inject host-local media references into channel action paths expecting normalized media.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43532.json",
    "cwe_ids": [
        "CWE-184"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/openclaw/openclaw

Affected ranges

Type
GIT
Repo
https://github.com/openclaw/openclaw
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2026.4.7"
        },
        {
            "fixed": "2026.4.10"
        }
    ]
}

Affected versions

v2026.*
v2026.4.7
v2026.4.7-1
v2026.4.8
v2026.4.9
v2026.4.9-beta.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43532.json"