Filesystem Boundary Bypass Vulnerability in OpenClaw by OpenClaw
CVE-2026-35658

6MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
10 April 2026

What is CVE-2026-35658?

OpenClaw before version 2026.3.2 is susceptible to a filesystem boundary bypass vulnerability within its image processing tool. This flaw allows attackers to circumvent the tools.fs.workspaceOnly restrictions, enabling them to traverse outside designated workspace areas and access files that should otherwise be protected by other filesystem tools. This loophole poses significant risks as it could expose sensitive data and systems to unauthorized access. Users of OpenClaw are advised to upgrade to the latest version to mitigate this risk.

Affected Version(s)

OpenClaw 0 < 2026.3.2

OpenClaw 2026.3.2

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Edward-x (@YLChen-007)
.