
🚨*CVE* CVE-2026-42438 OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media attachment read helper that allows unauthorized lo… https://www.cve.org/CVERecord?id=CVE-2026-42438 ----- Traducción: CVE-2026-42438 Ope… http://infoflow.cloud`
Post summary
OpenClaw 2026.4.9‑2026.4.10 contains a sender‑policy bypass in its host‑media attachment read helper, as documented in the CVE record. No PoC, exploit, or patch information was provided.

