PT-2026-35552 · Openclaw · Openclaw

Antaisecuritylab

·

Published

2026-04-02

·

Updated

2026-04-29

·

CVE-2026-41364

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description A symlink following issue exists in the SSH sandbox tar upload process. This allows remote attackers to write arbitrary files by uploading tar archives containing symbolic links (symlinks), which are files that point to another file or directory, to escape the sandbox and overwrite files on the remote host.
Recommendations Update to version 2026.3.31 or later.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41364
GHSA-5799-3XG7-RFRV
GHSA-FV94-QVG8-XQPW

Affected Products

Openclaw