Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
OpenClaw Feishu Media Download Can Write Files Outside of Safe Location
GHSA-vj3g-5px3-gr46
CVE-2026-22171
Summary
OpenClaw's Feishu media download feature can allow an attacker to write files to any location on the server by manipulating the Feishu media key. This is a security risk because it could allow an attacker to gain unauthorized access to the server. To fix this issue, OpenClaw has released a new version (2026.2.19) that ensures media downloads are written to safe locations and validates incoming Feishu keys.
What to do
- Update steipete openclaw to version 2026.2.19.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| steipete | openclaw | <= 2026.2.19 | 2026.2.19 |
Original title
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpolated directly into temporary file paths in exten...
Original description
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpolated directly into temporary file paths in extensions/feishu/src/media.ts. An attacker who can control Feishu media key values returned to the client can use traversal segments to escape os.tmpdir() and write arbitrary files within the OpenClaw process permissions.
osv CVSS4.0
8.3
Vulnerability type
CWE-22
Path Traversal
- https://github.com/openclaw/openclaw/security/advisories/GHSA-vj3g-5px3-gr46 URL
- https://github.com/openclaw/openclaw/commit/c821099157a9767d4df208c6b12f21494650... URL
- https://github.com/openclaw/openclaw/commit/cdb00fe2428000e7a08f9b7848784a004917... URL
- https://github.com/openclaw/openclaw/commit/ec232a9e2dff60f0e3d7e827a7c868db5254... URL
- https://github.com/openclaw/openclaw Product
- https://www.vulncheck.com/advisories/openclaw-path-traversal-in-feishu-media-tem...
Published: 18 Mar 2026 · Updated: 18 Mar 2026 · First seen: 18 Mar 2026