
CVE-2026-33581 OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUr… https://www.cve.org/CVERecord?id=CVE-2026-33581
Post summary
The text announces CVE‑2026‑33581, a sandbox bypass in OpenClaw that permits arbitrary local file reads using mediaUrl and fileUr.
