PT-2026-31767 · Openclaw · Openclaw

Edward-X

·

Published

2026-03-26

·

Updated

2026-04-10

·

CVE-2026-35632

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions through 2026.2.22
Description OpenClaw through version 2026.2.22 has a symlink traversal issue in the agents.create and agents.update handlers. These handlers use fs.appendFile on IDENTITY.md without proper symlink containment checks. An attacker with workspace access can create symlinks to append content to arbitrary files. This can lead to remote code execution through crontab injection or unauthorized access via SSH key manipulation.
Recommendations Update OpenClaw to a version later than 2026.2.22.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-35632
GHSA-7XR2-Q9VF-X4R5
GHSA-PMF3-2Q63-JMP6

Affected Products

Openclaw