CVE-2026-32846 | OpenClaw up to 2026.3.23 Path Validation isLikelyLocalPath path traversal (GHSA-f6pf-4gjx-c94r / EUVD-2026-16248)
A vulnerability was found in OpenClaw up to 2026.3.23. It has been rated as critical. The affected element is the function isLikelyLocalPath of the component Path Validation Handler. This manipulation causes path traversal.
The identification of this vulnerability is CVE-2026-32846. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to install a patch to address this issue.