Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m8v2-6wwh-r4gc

Опубликовано: 03 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7

Описание

OpenClaw's sandbox bind validation could bypass allowed-root and blocked-path checks via symlink-parent missing-leaf paths

Summary

In openclaw up to and including 2026.2.23 (latest npm release as of February 24, 2026), sandbox bind-source validation could be bypassed when a bind source used a symlinked parent plus a non-existent leaf path.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected: <= 2026.2.23
  • Patched: >= 2026.2.24 (planned next release)

Root Cause

validateBindMounts previously relied on full-path realpath only when the full source path already existed. For missing-leaf paths, parent symlink traversal was not fully canonicalized before allowed-root and blocked-path checks.

Security Impact

A source path that looked inside an allowed root could resolve outside that root (including blocked runtime paths) once the missing leaf was created, weakening sandbox bind-source boundary enforcement.

Fix

The validation path now canonicalizes through the nearest existing ancestor, then always re-checks the canonical path against both:

  • allowed source roots
  • blocked runtime paths

Verification

  • pnpm check
  • pnpm exec vitest run --config vitest.gateway.config.ts
  • pnpm test:fast
  • Added regression tests for symlink-parent + missing-leaf bypass patterns.

Fix Commit(s)

  • b5787e4abba0dcc6baf09051099f6773c1679ec1

Release Process Note

patched_versions is pre-set to the planned next release (2026.2.24) so after npm publish the advisory can be published without further field edits.

OpenClaw thanks @tdjackey for reporting.

Publication Update (2026-02-25)

openclaw@2026.2.24 is published on npm and contains the fix commit(s) listed above. This advisory now marks >= 2026.2.24 as patched.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

<= 2026.2.23

2026.2.24

EPSS

Процентиль: 17%
0.00254
Низкий

7 High

CVSS4

Дефекты

CWE-22
CWE-59

Связанные уязвимости

CVSS3: 6.1
nvd
5 месяцев назад

OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowed-root and blocked-path checks via symlinked parent directories with non-existent leaf paths. Attackers can craft bind source paths that appear within allowed roots but resolve outside sandbox boundaries once missing leaf components are created, weakening bind-source isolation enforcement.

CVSS3: 6.1
fstec
6 месяцев назад

Уязвимость функции validateBindMounts() ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю обойти существующие механизмы безопасности

EPSS

Процентиль: 17%
0.00254
Низкий

7 High

CVSS4

Дефекты

CWE-22
CWE-59