PT-2026-26011 · Openclaw · Openclaw
CVSS v3.1
5.3
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.2
Description
OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass in browser output handling. This allows writes outside of intended root directories. Attackers can exploit insufficient canonical path-boundary validation in file write operations to bypass root-bound restrictions and write files to arbitrary locations. The issue involves insufficient validation of path boundaries during file write operations, enabling attackers to escape root-bound restrictions. The fix unifies root-bound, file-descriptor-verified write semantics and canonical path-boundary validation across browser output and related install/skills write paths.
Recommendations
Update OpenClaw to version 2026.3.2 or later.
Exploit
Correção
Link Following
Time Of Check To Time Of Use
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openclaw