Executive brief
OpenClaw is an AI agent orchestration platform. A flaw in how it processes avatar image paths allows attackers to use symbolic links to read arbitrary files on the gateway server and exfiltrate them as base64-encoded data URLs through API responses. This could expose sensitive configuration files, credentials, or other data accessible to the gateway process.
Technical details
The vulnerability is a symlink traversal (CWE-59) in the resolveIdentityAvatarUrl function in src/gateway/session-utils.ts. The gateway processes local avatar paths without validating that they resolve within the intended workspace directory, allowing an attacker to craft a path containing symbolic links that escape the workspace boundary. When the gateway reads such a file, its contents are returned as a base64 data: URL in agents.list API responses. The attack is local in nature (requires the ability to place files/symlinks in the agent workspace) and does not require authentication. The fix involves using realpath() for canonical path resolution, enforcing containment checks, opening files with O_NOFOLLOW, and comparing inode/device pairs to prevent time-of-check/time-of-use races.
Affected products
- OpenClaw openclaw introduced in v2026.1.21; affected <= 2026.2.21-2; patched in 2026.2.22
Timeline
- 2026-02-23: disclosed
- 2026-02-22: patched: Fix commit 3d03375 authored; planned release 2026.2.22
- 2026-03-04: advisory