PT-2026-27237 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-23

·

Updated

2026-03-24

·

CVE-2026-32903

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.2
Description The software contains a symlink traversal issue within the stageSandboxMedia component. This allows attackers to overwrite files outside the designated sandbox workspace. The issue stems from unvalidated destination paths during media inbound writes, enabling exploitation through symlink traversal to overwrite host files beyond the intended sandbox boundaries.
Recommendations Update to version 2026.3.2 or later.

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2026-32903

Affected Products

Openclaw