PT-2026-25136 · Npm · Openclaw
Publicado
2026-03-02
·
Atualizado
2026-03-02
CVSS v4.0
8.7
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Summary
A symlink-retarget TOCTOU race in
writeFileWithinRoot could point an attacker-controlled path alias outside the configured root between resolution and write operations.Impact
Affected versions could cause out-of-root write side effects (including file creation or truncation) before final boundary validation.
Fix
Root-scoped write flow now opens existing files without pre-truncation, creates missing files with exclusive create semantics, truncates only after post-open identity/boundary checks, and removes out-of-root artifacts when a race is detected.
Affected and Patched Versions
- Affected:
<= 2026.2.26 - Patched:
2026.3.1
Correção
Link Following
Time Of Check To Time Of Use
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openclaw