Логотип exploitDog
bind:CVE-2026-32033
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-32033

Количество 2

Количество 2

nvd логотип

CVE-2026-32033

15 дней назад

OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass workspace-only file-system boundary validation due to canonicalization mismatch. Attackers can exploit this by crafting @-prefixed paths like @/etc/passwd to read files outside the intended workspace boundary when tools.fs.workspaceOnly is enabled.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27cr-4p5m-74rj

около 1 месяца назад

OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-32033

OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass workspace-only file-system boundary validation due to canonicalization mismatch. Attackers can exploit this by crafting @-prefixed paths like @/etc/passwd to read files outside the intended workspace boundary when tools.fs.workspaceOnly is enabled.

CVSS3: 6.5
0%
Низкий
15 дней назад
github логотип
GHSA-27cr-4p5m-74rj

OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths

CVSS3: 7.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу