screen_record outPath bypassed workspace-only filesystem guard.
openclaw< 2026.4.10>= 2026.4.10The node-host screen recording tool could honor an outPath outside the workspace guard, allowing an authorized tool call to write outside the intended workspace boundary.
The fix applies the workspace-root guard to node tool outPath handling, including screen recording paths.
The issue was fixed in #63551. The first stable tag containing the fix is v2026.4.10, and openclaw@2026.4.14 includes the fix.
635bb35b68d8faa5bfa2fda35feadd315122748aUsers should upgrade to openclaw 2026.4.10 or newer. The latest npm release, 2026.4.14, already includes the fix.
Thanks to @anshumanbh for reporting this issue.
{
"cwe_ids": [
"CWE-22",
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-17T21:58:24Z",
"nvd_published_at": null,
"severity": "MODERATE"
}