Executive brief
NearAI IronClaw is an agent operating system designed for privacy and security. A vulnerability in its file-writing tool allows an attacker to bypass security restrictions and write files outside of the designated safe folder. This could lead to the corruption of system files, unauthorized data modification, or the disruption of other projects running on the same system.
Technical details
A path traversal vulnerability exists in the `validate_path` function within `src/tools/builtin/path_utils.rs` of NearAI IronClaw. The validator fails to properly resolve symlinks when the final component of a path is a dangling symlink. While the validator treats such paths as non-existent files within the sandbox, the subsequent `tokio::fs::write` operation follows the symlink, allowing an attacker with local access to write or overwrite files outside the intended `base_dir`. This occurs because the validation logic only canonicalizes existing ancestors and appends the unresolved lexical tail. A patch has been released (commit 369ff3d) to address this logic mismatch.
Affected products
- nearai ironclaw up to 0.29.1
Timeline
- 2026-07-18: advisory: CVE-2026-16130 published via VulDB/NVD
- 2026-07-18: patched: Patch 369ff3d240cf3c0787b50e1e9f182e1a06c71255 identified
References
- https://github.com/nearai/ironclaw/
- https://github.com/nearai/ironclaw/commit/369ff3d240cf3c0787b50e1e9f182e1a06c71255
- https://github.com/nearai/ironclaw/issues/4797
- https://github.com/nearai/ironclaw/pull/4869
- https://vuldb.com/cve/CVE-2026-16130
- https://vuldb.com/submit/856883
- https://vuldb.com/vuln/379848