Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-36h3-7c54-j27r

Опубликовано: 02 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.8

Описание

OpenClaw has browser trace/download path symlink escape in temp output handling

Summary

Browser trace/download output path handling allowed symlink-root and symlink-parent escapes from the managed temp root.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published npm version: 2026.2.24
  • Affected versions: <= 2026.2.24
  • Planned patched release: 2026.2.25

Impact

An attacker with relevant local foothold and ability to influence output paths could route writes outside the intended temp root via symlink traversal, leading to arbitrary file overwrite.

Fix Commit(s)

  • 496a76c03ba85e15ea715e5a583e498ae04d36e3

Release Process Note

patched_versions is pre-set to the release (2026.2.25) so once npm 2026.2.25 is published, the advisory is published.

OpenClaw thanks @tdjackey for reporting.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

< 2026.2.25

2026.2.25

EPSS

Процентиль: 3%
0.00126
Низкий

6.8 Medium

CVSS4

Дефекты

CWE-22
CWE-59

Связанные уязвимости

CVSS3: 6.5
nvd
5 месяцев назад

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local attackers to escape the managed temp root directory. An attacker with local access can create symlinks to route file writes outside the intended temp directory, enabling arbitrary file overwrite on the affected system.

EPSS

Процентиль: 3%
0.00126
Низкий

6.8 Medium

CVSS4

Дефекты

CWE-22
CWE-59