GHSA-58q2-7r52-jq62

Suggest an improvement
Source
https://github.com/advisories/GHSA-58q2-7r52-jq62
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-58q2-7r52-jq62/GHSA-58q2-7r52-jq62.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-58q2-7r52-jq62
Aliases
Downstream
Published
2026-04-03T03:06:18Z
Modified
2026-07-08T08:12:16Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw: Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read
Details

Summary

Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read

Current Maintainer Triage

  • Normalized severity: medium
  • Assessment: v2026.3.28 ACP dispatch still reads attachment paths outside the guarded attachment-cache or root checks, and the root-enforcement fix is not yet shipped.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published npm version: 2026.3.31
  • Vulnerable version range: <=2026.3.28
  • Patched versions: >= 2026.3.31
  • First stable tag containing the fix: v2026.3.31

Fix Commit(s)

  • 566fb73d9da2d73c0be0d9b8e5b762e4dcd8e81d — 2026-03-30T14:04:02+01:00

OpenClaw thanks @north-echo for reporting.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-03T03:06:18Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.3.31

Database specific

last_known_affected_version_range
"<= 2026.3.28"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-58q2-7r52-jq62/GHSA-58q2-7r52-jq62.json"