Executive brief
OpenClaw is a development tool that runs untrusted code in a sandboxed workspace to safely apply patches and execute operations. A vulnerability in its symlink handling could allow an attacker with local access to redirect write operations outside the intended sandbox boundaries, potentially compromising host system files that should be protected.
Technical details
The vulnerability is a sandbox boundary bypass in symlink alias handling (CWE-59, CWE-367) affecting versions ≤2026.2.25. During workspace-only write operations (including apply_patch), the sandbox validation logic incorrectly accepts dangling symlinks with missing targets under certain conditions, allowing resolution outside the configured workspace root. An attacker with local privileges can exploit this by crafting symlink chains that resolve to paths outside the sandbox. The fix (commit 4fd29a3) validates symlink targets through existing ancestors and fails closed when canonical resolution escapes the boundary. A patch is available in version 2026.2.26.
Affected products
- OpenClaw OpenClaw ≤2026.2.25
Timeline
- 2026-02-26: disclosed
- 2026-02-26: patched: Fix commit 4fd29a35bb85a1898ebff518364c467058b50e14; patch released as version 2026.2.26