highVulnerability
GHSA-x82f-27x3-q89c
### Summary A symlink-retarget TOCTOU race in `writeFileWithinRoot` could point an attacker-controlled path alias outside the configured root between resolution and write operations. ### Impact Affected versions could cause out-of-root write side effects (including file creation or truncation) before final boundary validation. ### Fix Root-scoped write flow now opens existing files without pre-truncation, creates missing files with exclusive create semantics, truncates only after post-open identity/boundary checks, and removes out-of-root artifacts when a race is detected. ### Affected and Patched Versions - Affected: `<= 2026.2.26` - Patched: `2026.3.1`
Properties
- ghsa_id
- GHSA-x82f-27x3-q89c
- severity
- high
- summary
- OpenClaw's TOCTOU symlink race in writeFileWithinRoot could create or truncate files outside root boundaries
- cve_id
- GHSA-x82f-27x3-q89c
- is_ghsa_only
- true
- ghsa_published
- 2026-03-02T21:55:25Z
- source_url
- https://github.com/advisories/GHSA-x82f-27x3-q89c
- ghsa_updated
- 2026-03-02T21:55:26Z
Related Entities (4)
AFFECTS (1)
→[Software]npm/OpenClaw
HAS_WEAKNESS (2)
→[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition
→[Weakness]Improper Link Resolution Before File Access ('Link Following')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph