PT-2026-31969 · Openclaw · Openclaw
Edward-X
·
Published
2026-03-26
·
Updated
2026-04-10
·
CVE-2026-35658
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.2
Description
The
image tool did not fully enforce the tools.fs.workspaceOnly filesystem boundary. This allowed traversal of sandbox bridge mounts outside the workspace, enabling reading of files that other filesystem tools would reject.Recommendations
Update to version 2026.3.2 or later.
Fix
Exposure of Resource to Wrong Sphere
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw