PT-2026-27237 · Openclaw · Openclaw

·

CVE-2026-32903

·

Publicado

2026-03-23

·

Atualizado

2026-03-24

CVSS v3.1

6.1

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.2
Description The software contains a symlink traversal issue within the stageSandboxMedia component. This allows attackers to overwrite files outside the designated sandbox workspace. The issue stems from unvalidated destination paths during media inbound writes, enabling exploitation through symlink traversal to overwrite host files beyond the intended sandbox boundaries.
Recommendations Update to version 2026.3.2 or later.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32903

Produtos afetados

Openclaw