Junglewise Threat Intelligence

CVE-2026-27545: OpenClaw Node system.run approval bypass via parent-symlink cwd rebind

CVE-2026-27545 · Severity: medium · CVSS 4 · Published 2026-03-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a Node.js library that manages execution of system commands with an approval workflow. An attacker can bypass command approval controls by modifying a symbolic link in the parent directory between when a command is approved and when it executes. This allows a command approved for one location to run from an attacker-controlled location, potentially executing unintended or malicious operations.

Technical details

The vulnerability is a time-of-check-time-of-use (TOCTOU) race condition combined with improper symlink handling (CWE-367, CWE-59). For Node host executions, the approval context validates the current working directory (cwd) at approval time, but does not prevent modification of mutable parent symlinks between approval and execution. An attacker with write access to parent directories can rebind a symlink while keeping the visible cwd string unchanged, causing the approved command to execute from a different filesystem location. The fix adds immutable approval-time plan preparation with canonical fields (argv, cwd, agentId, sessionKey), enforces these values through storage and sanitization, and rejects mutable parent-symlink components during approval-plan building. Patched in version 2026.2.26 and later.

Affected products

  • OpenClaw openclaw <= 2026.2.25

Timeline

  • 2026-03-02: disclosed
  • 2026-02-26: patched: Fix commits available; version 2026.2.26 release pending

References

Related threats