---
id: CVE-2026-34510
title: OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loaders
summary: >-
  OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows
  media loaders that accepts remote-host file URLs and UNC-style paths before
  local-path validation. Attackers can exploit this by providing network-hosted
  file t…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-41
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.3.22
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-04-01T17:53:51.939850Z'
published: '2026-04-01'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:17:30.144Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-34510'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-h3x4-hc5v-v2gm
    label: GitHub Security Advisory (GHSA-h3x4-hc5v-v2gm)
  - url: >-
      https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87
    label: 'Patch Commit #1'
  - url: >-
      https://github.com/openclaw/openclaw/commit/4fd7feb0fd4ec16c48ed983980dba79a09b3aaf5
    label: 'Patch Commit #2'
  - url: >-
      https://github.com/openclaw/openclaw/commit/93880717f1cd34feaa45e74e939b7a5256288901
    label: 'Patch Commit #3'
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-remote-file-url-acceptance-in-windows-media-loaders
tags:
  - cve.org
epss: 0.00465
epssPercentile: 0.37762
ingestedAt: '2026-09-24T15:45:56.733Z'
---

## Overview

OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file targets that are treated as local content, bypassing intended access restrictions.

## Affected

- `OpenClaw < 2026.3.22`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
