Back

HIGH

OpenClaw < 2026.3.31 - Arbitrary File Write via Symlink Following in SSH Sandbox Tar Upload

Published Apr 27, 2026

Description

OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sandbox and overwrite files on the remote host.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 27, 2026
Updated Apr 29, 2026
Reserved Apr 20, 2026
CISA Vulnrichment
Updated Apr 29, 2026
NVD
Status Analyzed
Modified Jul 24, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Apr 27, 2026
Updated Apr 29, 2026
Exploited since n/a
EUVD-2026-25944 GHSA-FV94-QVG8-XQPW