Junglewise Threat Intelligence

OpenClaw agent avatar symlink traversal

Severity: medium · CVSS 4 · Published 2026-03-04

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI agent orchestration platform. A flaw in how it processes avatar image paths allows attackers to use symbolic links to read arbitrary files on the gateway server and exfiltrate them as base64-encoded data URLs through API responses. This could expose sensitive configuration files, credentials, or other data accessible to the gateway process.

Technical details

The vulnerability is a symlink traversal (CWE-59) in the resolveIdentityAvatarUrl function in src/gateway/session-utils.ts. The gateway processes local avatar paths without validating that they resolve within the intended workspace directory, allowing an attacker to craft a path containing symbolic links that escape the workspace boundary. When the gateway reads such a file, its contents are returned as a base64 data: URL in agents.list API responses. The attack is local in nature (requires the ability to place files/symlinks in the agent workspace) and does not require authentication. The fix involves using realpath() for canonical path resolution, enforcing containment checks, opening files with O_NOFOLLOW, and comparing inode/device pairs to prevent time-of-check/time-of-use races.

Affected products

  • OpenClaw openclaw introduced in v2026.1.21; affected <= 2026.2.21-2; patched in 2026.2.22

Timeline

  • 2026-02-23: disclosed
  • 2026-02-22: patched: Fix commit 3d03375 authored; planned release 2026.2.22
  • 2026-03-04: advisory

References

Related threats