Junglewise Threat Intelligence

CVE-2026-27485: OpenClaw symlink following in skill packaging script

CVE-2026-27485 · Severity: medium · CVSS 4 · Published 2026-02-20

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a platform for packaging and distributing skills (modular extensions). A local packaging script followed symlinks when building skill archives, potentially allowing an attacker who controls skill source files to include unintended files from the developer's machine in the final package. This could leak sensitive files from the packaging environment.

Technical details

The vulnerability is a symlink-following flaw (CWE-61/CWE-59) in the package_skill.py script used to build .skill archives. The script fails to reject or validate symlinks during archive creation; if an attacker-controlled skill directory contains symlinks pointing outside the skill root, those external files can be included in the resulting archive. Attack requires local execution (a skill author must run the packaging script on attacker-controlled skill content), and there is no remote trigger via normal OpenClaw runtime paths. The fix involves rejecting symlinks during packaging and adding regression tests. Patches are available in commits c275932aa4230fb7a8212fe1b9d2a18424874b3f and ee1d6427b544ccadd73e02b1630ea5c29ba9a9f0, with version 2026.2.18 patching the issue.

Affected products

  • OpenClaw openclaw <= 2026.2.17

Timeline

  • 2026-02-20: disclosed: Advisory published
  • 2026-02-18: patched: Fix released in version 2026.2.18

References

Related threats