Link Following Vulnerability in mf-yang Openclaw-CN Tool
CVE-2026-19008
Key Information:
- Vendor
Mf-yang
- Status
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-19008?
A security loophole exists in the mf-yang openclaw-cn tool, specifically within the assertNoSymlinkEscape function of the sandbox-paths.ts file. This flaw permits link following, which can be exploited to manipulate the system remotely. The vulnerability, publicly known, has not yet been addressed by the developers despite prior notification through an issue report. The potential for remote execution poses a significant risk, underscoring the necessity for immediate remediation.
Affected Version(s)
openclaw-cn 0.2.0
openclaw-cn 0.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
