CVE-2026-25475 | OpenClaw/Clawdbot/Moltbot up to 2026.1.29 src/media/parse.ts isValidMedia information disclosure (GHSA-r8g4-86fx-92mq / Nessus ID 298450)
A vulnerability was found in OpenClaw, Clawdbot and Moltbot up to 2026.1.29. It has been declared as problematic. This affects the function isValidMedia of the file src/media/parse.ts. Executing a manipulation can lead to information disclosure.
The identification of this vulnerability is CVE-2026-25475. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.