PT-2026-21336 · Openclaw · Openclaw

Aether-Ai-Agent

·

Published

2026-02-20

·

Updated

2026-03-01

·

CVE-2026-27485

CVSS v4.0

4.6

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.2.17 and earlier
Description OpenClaw, a personal AI assistant, contains an issue in the skills/skill-creator/scripts/package skill.py script. This script previously followed symbolic links when creating .skill archives. If an author runs this script on a crafted skill directory containing symlinks to files outside the skill root, the resulting archive can include unintended file contents. This can lead to the potential unintentional disclosure of local files from the packaging machine into a generated .skill artifact. Exploitation requires local execution of the packaging script on attacker-controlled skill contents. The vulnerable component is the package skill.py script.
Recommendations Versions prior to 2026.2.18 are affected. Reject symlinks during skill packaging. Add regression tests for symlink file and symlink directory cases. Update packaging guidance to document the symlink restriction.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27485
GHSA-R6H2-5GQQ-V5V6

Affected Products

Openclaw