PT-2026-25099 · Npm · Openclaw

Publicado

2026-03-02

·

Atualizado

2026-03-02

CVSS v4.0

6.8

Média

VetorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Summary

Browser trace/download output path handling allowed symlink-root and symlink-parent escapes from the managed temp root.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published npm version: 2026.2.24
  • Affected versions: <= 2026.2.24
  • Planned patched release: 2026.2.25

Impact

An attacker with relevant local foothold and ability to influence output paths could route writes outside the intended temp root via symlink traversal, leading to arbitrary file overwrite.

Fix Commit(s)

  • 496a76c03ba85e15ea715e5a583e498ae04d36e3

Release Process Note

patched versions is pre-set to the release (2026.2.25) so once npm 2026.2.25 is published, the advisory is published.
OpenClaw thanks @tdjackey for reporting.

Correção

Path traversal

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-36H3-7C54-J27R

Produtos afetados

Openclaw