Symlink Traversal Vulnerability in OpenClaw by OpenClaw
CVE-2026-35632

6.9MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
9 April 2026

What is CVE-2026-35632?

OpenClaw versions prior to 2026.2.22 are vulnerable to a symlink traversal issue in the agents.create and agents.update handlers. This vulnerability arises from the improper handling of filesystem appends to IDENTITY.md, which allows attackers with workspace access to create symlinks. Exploitation can enable attackers to append their own content to sensitive files, potentially leading to unauthorized access via SSH key manipulation or remote code execution through crontab injection. Users are advised to upgrade to the latest version to mitigate this risk.

Affected Version(s)

OpenClaw 0

OpenClaw None

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Edward-x (@YLChen-007)
.