discord
openclaw
| Version / range | Status | Type |
|---|---|---|
| 0 to before 2026.9.3 | affected | semver |
| 2026.9.3 | unaffected | semver |
OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured media roots would otherwise reject, placing bytes from an out-of-policy local file into an outbound emoji or sticker upload. Exploitation requires access to the guild asset action and knowledge or derivation of a useful local path; the issue does not permit unrestricted filesystem browsing or code execution. The issue is fixed in @openclaw/discord 2026.9.3.
Risk score
6.0
CVSS 4.0
openclaw
| Version / range | Status | Type |
|---|---|---|
| 0 to before 2026.9.3 | affected | semver |
| 2026.9.3 | unaffected | semver |
6.0
CVSS 4.0
5.3
CVSS 3.1