PT-2026-26389 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-19

·

Updated

2026-03-19

·

CVE-2026-32007

CVSS v3.1

6.8

Medium

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply patch tool that allows attackers with sandbox access to modify files outside the workspace directory by exploiting inconsistent enforcement of workspace-only checks on mounted paths. Attackers can use apply patch operations on writable mounts outside the workspace root to access and modify arbitrary files on the system.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-32007

Affected Products

Openclaw