Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgjq-7pq9-cvwp

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.6
CVSS3: 7.1

Описание

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.

EPSS

Процентиль: 16%
0.00246
Низкий

7.6 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.1
nvd
около 1 месяца назад

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.

EPSS

Процентиль: 16%
0.00246
Низкий

7.6 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-59