PT-2026-27237 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-32903

CVSS v3.1

6.1

Medium

AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
OpenClaw before 2026.3.2 contains a symlink traversal vulnerability in stageSandboxMedia that allows attackers to overwrite files outside the sandbox workspace. Attackers can exploit unvalidated destination paths in media/inbound writes to follow symlinks and overwrite host files beyond intended sandbox boundaries.

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2026-32903

Affected Products

Openclaw