Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-32054

5 месяцев назад

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local attackers to escape the managed temp root directory. An attacker with local access can create symlinks to route file writes outside the intended temp directory, enabling arbitrary file overwrite on the affected system.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36h3-7c54-j27r

6 месяцев назад

OpenClaw has browser trace/download path symlink escape in temp output handling

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-32054

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local attackers to escape the managed temp root directory. An attacker with local access can create symlinks to route file writes outside the intended temp directory, enabling arbitrary file overwrite on the affected system.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-36h3-7c54-j27r

OpenClaw has browser trace/download path symlink escape in temp output handling

0%
Низкий
6 месяцев назад

Уязвимостей на страницу