CVE-2026-25475Patch(openclaw / openclaw)

HIGHCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute paths, home directory paths, and directory traversal sequences. An agent can read any file on the system by outputting MEDIA:/path/to/file, exfiltrating sensitive data to the user/channel. This issue has been patched in version 2026.1.30.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-200

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-14); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-04: 1Mentions · 2026-02-10: 1Mentions · 2026-02-14: 2Mentions · 2026-02-17: 1Mentions · 2026-03-22: 1Exploit Tool / Code · 2026-03-22: 1Active Exploitation · 2026-03-22: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-17: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-17: 102-0402-1002-1402-1703-22
Signal classification4 categories
Patch
233.3%
General
233.3%
Disclosure
116.7%
Active Exploitation
116.7%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-041
Disclosure1
2026-02-101
Patch1
2026-02-142
General2
2026-02-171
Patch1
2026-03-221
Active Exploitation1
Full discourse6 posts
  • Coyote Security Scanner@CoyoteSecure
    General

    Just pushed v1.5 of Coyote, this was a big update, see details below: - Added scans for all five OpenClaw CVEs in openclaw .py: CVE-2026-25253 CVE-2026-24763 CVE-2026-25157 CVE-2026-25475 CVE-2026-25593 These include version-threshold detection plus config-risk indicators, and are now part of secure-openclaw output. - Updated version handling in OpenClaw report output in output .py so “outdated” uses the latest tracked OpenClaw fix level (2026.1.30). - Bumped Coyote version to 1.4.0 in:__init__.py README .md (displayed version text) - Updated OpenClaw command/help text in:__main__.py - Updated README OpenClaw section in:README .md to document all five CVEs, updated checks table, and refreshed example output. - Created the new doc: OpenClawCVEs .md with all OpenClaw CVEs Coyote scans for, fixed versions, and scan logic. - Added tests in: test_openclaw_security.py

    Post summary

    The update adds scanning and documentation for five OpenClaw CVEs, including detection logic and version tracking, but provides no exploit, patch, or detailed vulnerability information.

    43090369
    214 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25475 OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute path… https://www.cve.org/CVERecord?id=CVE-2026-25475

    Post summary

    The text discloses a path traversal vulnerability in OpenClaw’s isValidMedia() function prior to version 2026.1.30.

    01020318
    56.5K followersView on X
  • R Chong@Muawin_AI
    Active Exploitation

    8,646 AI agent instances exposed their credentials to the open internet. Not theoretical. CVE-2026-25475. Real users, real tokens, real damage. The tool was called OpenClaw. It fetched web pages for LLMs with no sanitization layer. This is the problem I quit my job to fix. 🧵

    Post summary

    The post reports active exploitation of CVE-2026-25475 via the OpenClaw tool, compromising thousands of AI agents and leaking credentials, with no patches or technical details provided.

    1001036
  • metad.ai@idatawill
    General

    🔎 社区验证: 这是已知问题! • GitHub Issue #8759: MEDIA 路径 • Issue #5151: Telegram 语音 • CVE-2026-25475: 安全漏洞 不是个例,很多人遇到过

    Post summary

    The post notes that CVE-2026-25475 is a known issue, citing community‑verified GitHub issues, but offers no further technical, exploit, or mitigation details.

    1000041
    13 followersView on X
  • Grok@grok
    Patch

    Updating to OpenClaw's latest release (v2026.2.9 as of Feb 9, 2026) includes patches for major known vulnerabilities like CVE-2026-25253 and CVE-2026-25475. Applying all official security suggestions—such as avoiding exposed instances and fixing misconfigurations—should mitigate most risks. However, yubrew's recent exploit analysis proposes additional fixes not yet merged in the repo, so check GitHub for updates. Always verify your setup.

    Post summary

    The message advises updating to OpenClaw v2026.2.9, which includes patches for CVE-2026-25253 and CVE-2026-25475, and recommends official security measures while noting additional fixes from an exploit analysis yet to be merged.

    1000052
    8.1M followersView on X
  • Grok@grok
    Patch

    Yes, the security risks with OpenClaw are indeed serious, including exposed instances enabling data leaks, prompt injections, and path traversal flaws like CVE-2026-25475. OpenAI has patched some in updates. To stay safe, run it in sandboxed environments, use strong auth, and scan skills with tools like Cisco's Skill Scanner. Check OpenAI's security updates for more.

    Post summary

    The message highlights security risks of OpenClaw and confirms that OpenAI has issued patches, advising users to adopt mitigations.

    0000060
    8.0M followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more