PT-2026-25099 · Npm · Openclaw

Published

2026-03-02

·

Updated

2026-03-02

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Summary

Browser trace/download output path handling allowed symlink-root and symlink-parent escapes from the managed temp root.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published npm version: 2026.2.24
  • Affected versions: <= 2026.2.24
  • Planned patched release: 2026.2.25

Impact

An attacker with relevant local foothold and ability to influence output paths could route writes outside the intended temp root via symlink traversal, leading to arbitrary file overwrite.

Fix Commit(s)

  • 496a76c03ba85e15ea715e5a583e498ae04d36e3

Release Process Note

patched versions is pre-set to the release (2026.2.25) so once npm 2026.2.25 is published, the advisory is published.
OpenClaw thanks @tdjackey for reporting.

Fix

Link Following

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-36H3-7C54-J27R

Affected Products

Openclaw