PT-2026-26223 · Openclaw · Openclaw

·

CVE-2026-27670

·

Publicado

2026-03-02

·

Atualizado

2026-03-21

CVSS v4.0

5.8

Média

VetorAV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.2
Description OpenClaw is affected by a race condition during ZIP file extraction. This allows local attackers to write files to locations outside the intended destination directory. The issue arises from a time-of-check-time-of-use race condition between path validation and file write operations. Attackers can exploit this by manipulating symlinks to redirect file writes outside the designated extraction root.
Recommendations Update OpenClaw to version 2026.3.2 or later.

Exploit

Correção

Link Following

Time Of Check To Time Of Use

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05023
CVE-2026-27670
GHSA-R54R-WMMQ-MH84

Produtos afetados

Openclaw