Junglewise Threat Intelligence

OpenClaw symlink traversal in browser trace and download path handling

Severity: low · CVSS 3.1 · Published 2026-03-21

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a development tool that generates browser trace and download files. A local attacker can exploit improper symlink handling in the temporary directory to write files outside the intended directory, potentially overwriting critical system files or gaining elevated access. This requires local system access but can lead to arbitrary file overwrite with no authentication needed.

Technical details

The vulnerability is a symlink traversal (CWE-59 / CWE-22) in OpenClaw's temp output path handling for browser trace and download functions. An attacker with local access can create symlinks pointing outside the managed temp root directory; the application fails to properly validate or resolve paths before following symlinks, allowing writes to arbitrary locations. The attack vector is local with low privilege requirements. An attacker can achieve arbitrary file overwrite on the affected system. The vulnerability is fixed in version 2026.2.25 and later (commit 496a76c03ba85e15ea715e5a583e498ae04d36e3).

Affected products

  • OpenClaw OpenClaw < 2026.2.25

Timeline

  • 2026-02-26: disclosed
  • 2026-02-26: patched: Fix released in version 2026.2.25
  • 2026-03-21: advisory: Advisory GHSA-ffr4-mrhv-vfr2 published (later withdrawn as duplicate)
  • 2026-03-27: other: Advisory GHSA-ffr4-mrhv-vfr2 withdrawn as duplicate of GHSA-36h3-7c54-j27r

References

Related threats