Link-Following Vulnerability in thClaws API by thClaws
CVE-2026-108839
2.3LOW
What is CVE-2026-108839?
The thClaws API version through 0.141.0 is susceptible to a link-following vulnerability in the post_inputs handler of the v1 API POST /v1/inputs endpoint. This flaw allows an attacker to exploit symlinks, potentially enabling unauthorized file writes or truncations outside the designated workspace by leveraging authenticated uploads. With the ability to plant symlinks under the allowed inputs/ prefix, attackers can manipulate file systems with increased privileges, creating significant security risks for users.
Affected Version(s)
thClaws 0 <= 0.141.0
