CVE-2026-35668 | OpenClaw up to 2026.3.23 Configuration Data fileUrl path traversal (GHSA-hr5v-j9h9-xjhg)
A vulnerability has been found in OpenClaw up to 2026.3.23 and classified as critical. Affected is an unknown function of the component Configuration Data Handler. This manipulation of the argument fileUrl causes path traversal.
This vulnerability is registered as CVE-2026-35668. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.