CVE-2026-26321 | OpenClaw/Clawdbot/Moltbot up to 2026.2.13 mediaUrl path traversal (GHSA-8jpq-5h99-ff5r)
A vulnerability was found in OpenClaw, Clawdbot and Moltbot up to 2026.2.13. It has been classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument mediaUrl leads to path traversal.
This vulnerability is documented as CVE-2026-26321. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.