PT-2026-26414 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-19
·
Updated
2026-03-19
·
CVE-2026-32033
CVSS v3.1
5.3
Medium
| AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass workspace-only file-system boundary validation due to canonicalization mismatch. Attackers can exploit this by crafting @-prefixed paths like @/etc/passwd to read files outside the intended workspace boundary when tools.fs.workspaceOnly is enabled.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw