Junglewise Threat Intelligence

OpenClaw skills-install-download path traversal via tools-root rebinding

Severity: low · CVSS 3.1 · Published 2026-03-29

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a popular Node.js library for managing skill installations and downloads. A vulnerability in the skills download installer allows a local attacker to bypass path validation and write files outside the intended tools directory by rebinding the validated path between checks and the actual file operations. This could allow installation of unauthorized components or code execution on affected systems.

Technical details

The vulnerability is a time-of-check-time-of-use (TOCTOU) race condition (CWE-367) in the skills-install-download component. The installer validates the tools root path lexically but then reuses the same mutable path variable during archive download and copy operations. A local attacker with file system access can rebind (e.g., via symbolic links or bind mounts) the validated tools-root path between validation and the final write, redirecting the installer to extract or write files outside the intended tools directory. The fix, released in OpenClaw 2026.3.8, canonicalizes the validated path immediately after validation and derives all subsequent download/copy operations from that canonical reference, preventing rebinding attacks.

Affected products

  • OpenClaw openclaw <= 2026.3.7

Timeline

  • 2026-03-11: disclosed: Advisory published on GitHub
  • 2026-03-08: patched: Fix released in OpenClaw v2026.3.8
  • 2026-03-29: other: Advisory republished as GHSA-6q2v-vfwp-pvwh (withdrawn as duplicate)
  • 2026-04-06: other: GHSA-6q2v-vfwp-pvwh withdrawn; original advisory is GHSA-vhwf-4x96-vqx2

References

Related threats