Executive brief
OpenClaw is a JavaScript library for extracting ZIP archives. A flaw in its ZIP extraction logic allowed attackers to write files outside the intended extraction directory if a symbolic link already existed in the target path. This could enable arbitrary file overwrite on systems using the library to handle untrusted archives.
Technical details
The vulnerability is a path confinement bypass (CWE-59) in the ZIP extraction logic in src/infra/archive.ts. The root cause is that output-path validation used lexical checks only, failing to account for symlinks that could traverse outside the extraction root during the actual write operation. An attacker with control over a ZIP archive being extracted can exploit this when a pre-existing symlink is present in the destination directory hierarchy. The vulnerability allows arbitrary file writes to locations outside the extraction root. The fix validates resolved destination paths against the extraction root, rejects symlinks in destination path segments, and uses no-follow file opens where supported. Patch 2026.2.22 addresses this issue.
Affected products
- OpenClaw openclaw <= 2026.2.21-2
Timeline
- 2026-03-03: disclosed: GHSA-jxrq-8fm4-9p58 advisory published
- 2026-02-21: patched: Fix commit 4b226b7 authored; planned patch release 2026.2.22