Home

Description

OpenClaw through 2026.2.22 contains a symlink traversal vulnerability in agents.create and agents.update handlers that use fs.appendFile on IDENTITY.md without symlink containment checks. Attackers with workspace access can plant symlinks to append attacker-controlled content to arbitrary files, enabling remote code execution via crontab injection or unauthorized access via SSH key manipulation.

PUBLISHED Reserved 2026-04-04 | Published 2026-04-09 | Updated 2026-05-25 | Assigner VulnCheck




MEDIUM: 6.9CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

HIGH: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Problem types

UNIX Symbolic Link (Symlink) Following

Product status

Default status
unaffected

Any version
affected

2026.2.23 (semver)
unaffected

Credits

Edward-x (@YLChen-007) reporter

References

github.com/...enclaw/security/advisories/GHSA-7xr2-q9vf-x4r5 exploit

github.com/...enclaw/security/advisories/GHSA-7xr2-q9vf-x4r5 (GitHub Security Advisory (GHSA-7xr2-q9vf-x4r5)) third-party-advisory

www.vulncheck.com/...y-md-appendfile-in-agents-create-update (VulnCheck Advisory: OpenClaw < 2026.2.22 - Symlink Traversal via IDENTITY.md appendFile in agents.create/update) third-party-advisory

cve.org (CVE-2026-35632)

nvd.nist.gov (CVE-2026-35632)

Download JSON