Executive brief
OpenClaw is a gateway service that manages file operations for workspace agents. A vulnerability in the agents.files.get and agents.files.set methods allows symlink traversal to read and write files outside the intended workspace directory. An authenticated attacker could exploit this to access or modify arbitrary files accessible to the gateway process, potentially leading to code execution depending on which files are overwritten.
Technical details
This vulnerability is a path traversal flaw (CWE-22, CWE-59) in the gateway's agents.files methods. The vulnerability stems from insufficient validation of symlinks when resolving workspace file paths; allowlisted workspace files that are symlinks can be crafted to resolve outside the agent workspace boundary. An authenticated user with permission to call agents.files.get or agents.files.set can leverage this to read or write files outside the workspace. The fix resolves real workspace paths, enforces containment for resolved targets, rejects out-of-workspace symlink targets, and maintains support for in-workspace symlinks. Patch available in version 2026.2.25 and later.
Affected products
- OpenClaw OpenClaw <= 2026.2.24
Timeline
- 2026-03-02: disclosed: Advisory published
- 2026-02-25: patched: Version 2026.2.25 released with fix