Junglewise Threat Intelligence

CVE-2026-27523: OpenClaw sandbox bind validation bypass via symlink-parent missing-leaf paths

CVE-2026-27523 · Severity: medium · CVSS 4 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a sandboxing library that restricts where container volumes can be mounted by validating bind paths against allowed roots and blocked paths. An attacker can bypass these security checks by using a symlinked parent directory combined with a non-existent file path, allowing container mounts to escape sandbox restrictions and access protected system directories.

Technical details

The vulnerability is a path traversal and link-following issue (CWE-22, CWE-59) in OpenClaw's validateBindMounts function. The root cause is incomplete canonicalization of symlinked paths when the full source path does not exist: the validation only performs full-path realpath resolution if the complete path already exists, but for missing-leaf paths it fails to canonicalize parent symlinks before checking against allowed-root and blocked-path policies. An attacker can craft a bind source using a symlinked parent plus a non-existent leaf filename; the path appears to fall within an allowed root during validation, but once the missing leaf is created, it resolves to a location outside the allowed boundary (potentially including blocked runtime paths). The fix applies realpath canonicalization through the nearest existing ancestor and re-validates the canonical path against both allowed and blocked directories. Patch version 2026.2.24 addresses this issue.

Affected products

  • OpenClaw OpenClaw <= 2026.2.23

Timeline

  • 2026-02-25: disclosed
  • 2026-02-25: patched: Version 2026.2.24 published on npm
  • 2026-03-03: advisory

References

Related threats