Junglewise Threat Intelligence

OpenClaw symlink traversal in agents.create/update via IDENTITY.md

Severity: low · CVSS 3.1 · Published 2026-04-10

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a popular open-source framework used to develop and manage AI agents. A symlink traversal vulnerability in the agents.create and agents.update handlers allows authenticated attackers with workspace access to plant malicious symlinks that cause arbitrary file writes. An attacker can inject commands into system files like crontabs or SSH keys, leading to remote code execution or unauthorized access to systems running OpenClaw.

Technical details

This is a symlink traversal vulnerability (CWE-61) in OpenClaw's agents.create and agents.update handlers. The handlers construct an IDENTITY.md path and use fs.appendFile to write agent metadata without verifying that the target path is not a symlink. An attacker with workspace access can plant a symlink pointing to a sensitive file (e.g., /etc/crontab, ~/.ssh/authorized_keys). When the handler runs, fs.appendFile follows the symlink and appends attacker-controlled content (agent name, emoji, avatar fields) to the target file. Attack precondition: ability to create files in the agent workspace. Impact ranges from remote code execution via crontab injection to persistent code execution via shell configuration or unauthorized SSH access. The vulnerability is an incomplete fix for CVE-2026-32013, as similar handlers were patched but agents.create/update were missed. No patch has been released as of the advisory date.

Affected products

  • OpenClaw OpenClaw through 2026.2.22

Timeline

  • 2026-04-10: disclosed: GHSA-pmf3-2q63-jmp6 published (later withdrawn as duplicate)
  • 2026-03-24: disclosed: GHSA-7xr2-q9vf-x4r5 published as primary advisory for incomplete fix of CVE-2026-32013
  • 2026-04-18: other: GHSA-pmf3-2q63-jmp6 withdrawn due to duplication with GHSA-7xr2-q9vf-x4r5

References

Related threats