mediumCVSS 6.1Vulnerability
GHSA-2cwr-f5hx-gg3w
## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-cfvj-7rx7-fc7c. This link is maintained to preserve external references. ## Original Description OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to validate destination symlinks during media staging, allowing writes to follow symlinks outside the sandbox workspace. Attackers can exploit this by placing symlinks in the media/inbound directory to overwrite arbitrary files on the host system outside sandbox boundaries.
Properties
- ghsa_id
- GHSA-2cwr-f5hx-gg3w
- severity
- medium
- summary
- Duplicate Advisory: OpenClaw: stageSandboxMedia destination symlink traversal can overwrite files outside sandbox workspace
- cvss_score
- 6.1
- cve_id
- GHSA-2cwr-f5hx-gg3w
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
- is_ghsa_only
- true
- ghsa_published
- 2026-03-19T03:30:57Z
- source_url
- https://github.com/advisories/GHSA-2cwr-f5hx-gg3w
- ghsa_updated
- 2026-03-19T16:26:20Z
Related Entities (3)
AFFECTS (1)
→[Software]npm/OpenClaw
HAS_WEAKNESS (1)
→[Weakness]Improper Link Resolution Before File Access ('Link Following')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph