HIGH
OpenClaw < 2026.3.2 - Symlink Traversal in stageSandboxMedia Destination
Published Mar 19, 2026
7.7
HIGHCVSS 4.0
EPSS 0.18%
Description
OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to validate destination symlinks during media staging, allowing writes to follow symlinks outside the sandbox workspace. Attackers can exploit this by placing symlinks in the media/inbound directory to overwrite arbitrary files on the host system outside sandbox boundaries.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.2
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-cfvj-7rx7-fc7c Advisory
- https://github.com/openclaw/openclaw/commit/17ede52a4be3034f6ec4b883ac6b81ad0101558a patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-cfvj-7rx7-fc7c vendor-advisoryMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-31990
- https://www.vulncheck.com/advisories/openclaw-symlink-traversal-in-stagesandboxmedia-destination third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-cfvj-7rx7-fc7c | Advisory | |
| https://github.com/openclaw/openclaw/commit/17ede52a4be3034f6ec4b883ac6b81ad0101558a | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-cfvj-7rx7-fc7c | vendor-advisoryMitigationVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-31990 | ||
| https://www.vulncheck.com/advisories/openclaw-symlink-traversal-in-stagesandboxmedia-destination | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 19, 2026
Updated Jun 23, 2026
Reserved Mar 10, 2026
Link CVE-2026-31990
CISA Vulnrichment
GHSA-CFVJ-7RX7-FC7C Updated Mar 19, 2026