PT-2026-35781 · Openclaw · Openclaw

Antaisecuritylab

·

Published

2026-04-03

·

Updated

2026-04-30

·

CVE-2026-41397

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description A sandbox escape allows attackers to traverse directory boundaries through symlink exploitation during file synchronization operations. Remote attackers can bypass sandbox restrictions by crafting malicious symlinks in mirror sync operations to access arbitrary files outside intended boundaries.
Recommendations Update to version 2026.3.31.

Fix

Unrestricted File Upload

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41397
GHSA-CWF8-44X6-32C2

Affected Products

Openclaw