PT-2026-26737 · Openclaw · Openclaw
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.26
Description
OpenClaw contains a path traversal issue in workspace boundary validation. This allows attackers to write files outside the designated workspace by utilizing in-workspace symbolic links that point to non-existent targets outside the root directory. The boundary check incorrectly resolves aliases, enabling the initial write operation to bypass the workspace boundary and create files in arbitrary locations.
Recommendations
Update OpenClaw to version 2026.2.26 or later.
Exploit
Correção
Link Following
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openclaw