Junglewise Threat Intelligence

CVE-2026-32024: OpenClaw avatar symlink traversal

CVE-2026-32024 · Severity: low · CVSS 3.1 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a widely-used open-source project management and collaboration tool. A vulnerability in its avatar handling allows attackers with local access to read sensitive files stored on the same server outside of the intended workspace boundaries, potentially exposing private configurations, keys, or other user data.

Technical details

The vulnerability is a symlink traversal (CWE-22, CWE-59) in OpenClaw's avatar resolution logic. In vulnerable versions, the application failed to properly validate and sanitize avatar file paths, allowing attackers to craft symlinks that escape the configured workspace directory. The attack requires local access (low privilege) to the server and does not require user interaction. An attacker can exploit this by creating a malicious symlink in the avatar directory that points to sensitive files outside the workspace, then accessing the avatar through gateway surfaces to read file contents. The fix hardens both gateway avatar metadata resolution (enforcing canonical containment and O_NOFOLLOW) and Control UI avatar serving (rejecting symlink paths and enforcing fd/file-identity checks). Version 2026.2.22 and later contain the patch.

Affected products

  • OpenClaw OpenClaw <=2026.2.21, 2026.2.21-1, 2026.2.21-2

Timeline

  • 2026-02-23: disclosed
  • 2026-02-23: patched: Version 2026.2.22 and later

References

Related threats