PT-2026-26223 · Openclaw · Openclaw

·

CVE-2026-27670

·

Published

2026-03-02

·

Updated

2026-03-21

CVSS v4.0

5.8

Medium

VectorAV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.2
Description OpenClaw is affected by a race condition during ZIP file extraction. This allows local attackers to write files to locations outside the intended destination directory. The issue arises from a time-of-check-time-of-use race condition between path validation and file write operations. Attackers can exploit this by manipulating symlinks to redirect file writes outside the designated extraction root.
Recommendations Update OpenClaw to version 2026.3.2 or later.

Exploit

Fix

Link Following

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05023
CVE-2026-27670
GHSA-R54R-WMMQ-MH84

Affected Products

Openclaw