| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fv94-qvg8-xqpw | OpenClaw: SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 29 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sandbox and overwrite files on the remote host. | |
| Title | OpenClaw < 2026.3.31 - Arbitrary File Write via Symlink Following in SSH Sandbox Tar Upload | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-29T14:05:55.863Z
Reserved: 2026-04-20T14:09:02.629Z
Link: CVE-2026-41364
Updated: 2026-04-29T14:05:52.030Z
Status : Analyzed
Published: 2026-04-28T00:16:25.410
Modified: 2026-04-28T18:45:44.107
Link: CVE-2026-41364
No data.
OpenCVE Enrichment
Updated: 2026-04-28T19:45:07Z
Github GHSA