
CVE-2026-41389 OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers… https://www.cve.org/CVERecord?id=CVE-2026-41389
Post summary
The tweet announces CVE‑2026‑41389, describing a local‑root containment failure in OpenClaw that permits arbitrary local and UNC file access, but does not report exploitation or patch information.

