CVE-2026-32013
CVE-2026-32013
8.7
HighPublished:
Last updated:
Source:disclosure@vulncheck.com
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- Low
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and writing files outside the agent workspace. Attackers can exploit symlinked allowlisted files to access arbitrary host files within gateway process permissions, potentially enabling code execution through file overwrite attacks.
References
disclosure@vulncheck.com
https://github.com/openclaw/openclaw/commit/125f4071bcbc0de32e769940d07967db47f09d3ddisclosure@vulncheck.com
https://github.com/openclaw/openclaw/security/advisories/GHSA-fgvx-58p6-gjwcdisclosure@vulncheck.com
https://www.vulncheck.com/advisories/openclaw-symlink-traversal-in-agents-files-methods