CVE-2026-32013 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and writ…
High CVSS: 8.7

CVE-2026-32013

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and writing files outside the agent workspace. Attackers can exploit symlinked allowlisted files to access arbitrary host files within gateway process permissions, potentially enabling code execution through file overwrite attacks.
Vendor
Openclaw
Product
Openclaw
CWE
CWE-59
Yayın Tarihi
2026-03-19 22:16:34
Güncelleme
2026-03-23 18:29:35
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar