PT-2026-57891 · Openclaw · Openclaw
CVSS v4.0
7.6
High
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.6.9
Description
A symlink following issue exists in the mirror sync feature. This allows lower-trust callers to bypass policy checks and authorization boundaries by exploiting remote symlink parents, enabling them to perform actions that require stronger authorization when the feature is enabled and reachable.
Recommendations
Update to version 2026.6.9 or later.
As a temporary mitigation, disable the mirror sync feature.
Exploit
Fix
Link Following
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw