Executive brief
OpenClaw is an AI-powered automation tool that performs actions on systems across operating systems and platforms. A timing vulnerability in the file-writing function allows attackers to redirect file operations to locations outside the intended protected directory, potentially creating or truncating arbitrary files on the system before the application's boundary checks can prevent it.
Technical details
The vulnerability is a time-of-check-to-time-of-use (TOCTOU) symlink race condition in the writeFileWithinRoot function (CWE-367, CWE-59). An attacker can retarget a symlink between the moment the application resolves the file path and the moment it performs the write operation, causing the function to create or truncate files outside the configured root directory. The flaw occurs because the application validates the file location before opening it, but an attacker can change the symlink target in the window between validation and file write. The vulnerability was patched in version 2026.3.1, which now opens existing files without pre-truncation, creates new files atomically, performs truncation only after post-open boundary checks, and cleans up any out-of-root artifacts when a race is detected.
Affected products
- OpenClaw OpenClaw <= 2026.2.26
Timeline
- 2026-03-02: disclosed
- 2026-03-01: patched: Version 2026.3.1