Executive brief
OpenClaw is a browser automation and AI agent tool that handles file operations during output generation. A vulnerability allowed attackers to write files outside the intended root directory by bypassing path confinement checks in browser output handling. This could lead to unauthorized file creation or modification in unintended locations on the system. The issue affects versions up to 2026.3.1 and is fixed in 2026.3.2.
Technical details
The vulnerability is a path-confinement bypass (CWE-59, CWE-367) in OpenClaw's browser output handling logic, allowing writes outside intended root boundaries. The root cause involves insufficient path validation and a time-of-check/time-of-use (TOCTOU) race condition in file write operations, particularly affecting symlink and hardlink handling. Exploitation requires local access with low privilege level and does not require user interaction. An attacker can achieve unauthorized file writes to arbitrary locations on the filesystem. The fix unifies root-bound file-descriptor-verified write semantics, implements canonical path-boundary validation across browser output and install/skills write paths, and adds regression coverage for symlink-rebind race conditions. Patch version 2026.3.2 was released on 2026-03-02.
Affected products
- OpenClaw openclaw <= 2026.3.1
Timeline
- 2026-03-03: disclosed: GHSA-3pxq-f3cp-jmxp published
- 2026-03-02: patched: Fix commit 104d32bb64cdf19d5e77f70553a511a2ae90ad1c released in version 2026.3.2