PT-2026-26394 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-02

·

Updated

2026-03-21

·

CVE-2026-32013

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.25
Description OpenClaw gateway agents contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods. This allows reading and writing files outside the agent workspace. Attackers can exploit symlinked allowlisted files to access arbitrary host files within gateway process permissions. This could potentially enable code execution through file overwrite attacks. The agents.files.get and agents.files.set methods previously allowed symlink traversal for allowlisted workspace files, where a symlinked allowlisted file could resolve outside the agent workspace.
Recommendations Versions prior to 2026.2.25 should be updated to version 2026.2.25 or later. The patch resolves real workspace paths, enforces containment for resolved targets, rejects out-of-workspace symlink targets, and keeps in-workspace symlink targets supported. The patch also adds gateway regression tests for blocked escapes and valid in-workspace symlink behavior.

Fix

Link Following

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-32013
GHSA-FGVX-58P6-GJWC

Affected Products

Openclaw