Mf Yang · Openclaw-Cn · CVE-2026-19008
**Name of the Vulnerable Software and Affected Versions**
mf-yang openclaw-cn versions prior to 0.2.2
**Description**
A remote attack is possible in the apply patch Tool component due to an issue in the `assertNoSymlinkEscape()` function within the src/agents/sandbox-paths.ts file. This flaw allows for link following, which occurs when a program follows a symbolic link to a location outside the intended directory.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict the use of the `assertNoSymlinkEscape()` function to minimize the risk of exploitation.