Executive brief
OpenClaw, a platform for managing agents and workspaces, contains a security flaw in how it handles agent identity files. An attacker with access to a workspace can trick the system into writing data to sensitive system files instead of the intended identity file. This can lead to a complete system takeover, unauthorized access via SSH, or the execution of malicious commands.
Technical details
A symlink traversal vulnerability exists in OpenClaw's 'agents.create' and 'agents.update' handlers within 'src/gateway/server-methods/agents.ts'. These handlers utilize the Node.js 'fs.appendFile' function on the 'IDENTITY.md' file without performing symlink resolution or workspace boundary checks. While 'ensureAgentWorkspace' uses the 'wx' flag to prevent file overwriting, it silently ignores 'EEXIST' errors if a symlink already exists. A local attacker with workspace access can plant a symbolic link at 'IDENTITY.md' pointing to sensitive system files like '/etc/crontab' or '~/.ssh/authorized_keys'. When the application appends agent metadata (name, emoji, avatar) to the identity file, it follows the symlink and writes the attacker-controlled content to the target file, potentially leading to Remote Code Execution (RCE) or privilege escalation.
Affected products
- OpenClaw openclaw <= 2026.2.22
Timeline
- 2026-03-24: advisory: Original advisory GHSA-7xr2-q9vf-x4r5 published
- 2026-04-09: disclosed: NVD publication of CVE-2026-35632
- 2026-04-18: other: Duplicate advisory GHSA-pmf3-2q63-jmp6 withdrawn