Raw vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSummary
CVE-2026-29611 is a high-severity External Control of File Name or Path (CWE-73) vulnerability in Openclaw Openclaw. Its CVSS base score is 8.2 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Data from Local System (T1005); ranked at the 22th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and AC-3 (Access Enforcement) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2026-29611 is a local file inclusion vulnerability affecting OpenClaw versions prior to 2026.2.14, specifically in the BlueBubbles extension when installed and enabled. The issue resides in the sendBlueBubblesMedia function, which fails to properly validate the mediaPath parameter against an allowlist. This flaw, classified under CWE-73, enables attackers to traverse directory boundaries and access arbitrary files on the local filesystem. The vulnerability carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), highlighting high confidentiality impact with network accessibility and no prerequisites.
Remote, unauthenticated attackers can exploit this vulnerability by supplying a malicious mediaPath parameter to the sendBlueBubblesMedia endpoint. Successful exploitation allows reading of sensitive local files, such as /etc/passwd, which are then exfiltrated as media attachments. The attack requires the BlueBubbles extension to be active but demands no user interaction or privileges, making it straightforward over the network.
Advisories recommend upgrading to OpenClaw version 2026.2.14 or later, where the fix is implemented via commit 71f357d9498cebb0efe016b0496d5fbe807539fc. Additional guidance from the GitHub security advisory (GHSA-rwj8-p9vq-25gv) and VulnCheck details disabling the BlueBubbles extension as a temporary mitigation if patching is not immediately feasible.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-9935
Vulnerability Data
OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be installed and enabled) media path handling that allows attackers to read arbitrary files from the local filesystem. The sendBlueBubblesMedia function fails to validate mediaPath…
more
parameters against an allowlist, enabling attackers to request sensitive files like /etc/passwd and exfiltrate them as media attachments.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V5.3.2
Mitigating Controls (NIST 800-53 r5) AI
Input validation directly rejects or sanitizes untrusted path strings before they reach filesystem operations.
Enforces authorization checks on the actual resource accessed, blocking unauthorized files even when a malicious path is supplied.
Least-privilege limits the set of files or directories any subject can affect, shrinking the blast radius of a path-control flaw.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect path-traversal issues but does not itself implement preventive controls.
Secure development lifecycle mandates input validation and path-handling controls that directly prevent external file/path manipulation.
Application security requirements explicitly call for controls against untrusted input influencing file operations.
Secure architecture principles discourage unsafe path construction but do not prescribe concrete file-name controls.
Secure coding standards require canonicalization, allow-listing, and bounds checks on file paths, directly eliminating CWE-73.
Information access restriction limits which files can be reached, indirectly reducing impact of path manipulation.