PT-2026-26389 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-19
·
Updated
2026-03-19
·
CVE-2026-32007
CVSS v3.1
6.8
Medium
| AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply patch tool that allows attackers with sandbox access to modify files outside the workspace directory by exploiting inconsistent enforcement of workspace-only checks on mounted paths. Attackers can use apply patch operations on writable mounts outside the workspace root to access and modify arbitrary files on the system.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw