screen_record outPath bypassed workspace-only filesystem guard.
openclaw< 2026.4.10>= 2026.4.10The node-host screen recording tool could honor an outPath outside the workspace guard, allowing an authorized tool call to write outside the intended workspace boundary.
The fix applies the workspace-root guard to node tool outPath handling, including screen recording paths.
The issue was fixed in #63551. The first stable tag containing the fix is v2026.4.10, and [email protected] includes the fix.
635bb35b68d8faa5bfa2fda35feadd315122748aUsers should upgrade to openclaw 2026.4.10 or newer. The latest npm release, 2026.4.14, already includes the fix.
Thanks to @anshumanbh for reporting this issue.
| Score | Percentile |
|---|---|
| 0.03% | 7.49% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 5.3 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-jf25-7968-h2h5 ↗ |
| CVE | CVE-2026-43567 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| npm | openclaw | < 2026.4.10 | 2026.4.10 | — |