PT-2026-26401 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-19

·

Updated

2026-03-19

·

CVE-2026-32020

CVSS v3.1

3.3

Low

AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symbolic links, allowing out-of-root file reads. Attackers can place symlinks under the Control UI root directory to bypass directory confinement checks and read arbitrary files outside the intended root.

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2026-32020

Affected Products

Openclaw