Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-62189

Опубликовано: 13 июл. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Версия до 2026.6.9 (исключая)

EPSS

Процентиль: 16%
0.00246
Низкий

7.1 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.1
github
около 1 месяца назад

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.

EPSS

Процентиль: 16%
0.00246
Низкий

7.1 High

CVSS3

Дефекты

CWE-59