PT-2026-31767 · Openclaw · Openclaw
Edward-X
·
Published
2026-03-26
·
Updated
2026-04-10
·
CVE-2026-35632
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions through 2026.2.22
Description
OpenClaw through version 2026.2.22 has a symlink traversal issue in the
agents.create and agents.update handlers. These handlers use fs.appendFile on IDENTITY.md without proper symlink containment checks. An attacker with workspace access can create symlinks to append content to arbitrary files. This can lead to remote code execution through crontab injection or unauthorized access via SSH key manipulation.Recommendations
Update OpenClaw to a version later than 2026.2.22.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw