CVE-2026-43532
OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media proc
OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media processing. Attackers can bypass media normalization to inject host-local media references into channel action paths expecting normalized media.
HIGH · CVSS 7.7
EPSS 0.00044
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0