highVulnerability

GHSA-x82f-27x3-q89c

### Summary A symlink-retarget TOCTOU race in `writeFileWithinRoot` could point an attacker-controlled path alias outside the configured root between resolution and write operations. ### Impact Affected versions could cause out-of-root write side effects (including file creation or truncation) before final boundary validation. ### Fix Root-scoped write flow now opens existing files without pre-truncation, creates missing files with exclusive create semantics, truncates only after post-open identity/boundary checks, and removes out-of-root artifacts when a race is detected. ### Affected and Patched Versions - Affected: `<= 2026.2.26` - Patched: `2026.3.1`

Properties

ghsa_id
GHSA-x82f-27x3-q89c
severity
high
summary
OpenClaw's TOCTOU symlink race in writeFileWithinRoot could create or truncate files outside root boundaries
cve_id
GHSA-x82f-27x3-q89c
is_ghsa_only
true
ghsa_published
2026-03-02T21:55:25Z
source_url
https://github.com/advisories/GHSA-x82f-27x3-q89c
ghsa_updated
2026-03-02T21:55:26Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition
[Weakness]Improper Link Resolution Before File Access ('Link Following')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph