CVE-2026-29611 | OpenClaw up to 2026.2.13 /etc/passwd sendBlueBubblesMedia mediaPath file inclusion (GHSA-rwj8-p9vq-25gv)
A vulnerability was found in OpenClaw up to 2026.2.13 and classified as problematic. This impacts the function sendBlueBubblesMedia of the file /etc/passwd. Executing a manipulation of the argument mediaPath can lead to file inclusion.
This vulnerability is tracked as CVE-2026-29611. The attack is restricted to local execution. No exploit exists.
It is suggested to upgrade the affected component.