CVE-2026-41364
HIGH severity · CVSS 8.1 · CWE-59
8.1CVSS HIGH
Summary
OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sandbox and overwrite files on the remote host.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactNone
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)1%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: https://github.com/openclaw/openclaw/commit/3d5af14984ac1976c747a8e11581d697bd0829dc ↗
Additional information
- NVD record
- https://github.com/openclaw/openclaw/commit/3d5af14984ac1976c747a8e11581d697bd0829dcPatch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-fv94-qvg8-xqpwAdvisory
- https://www.vulncheck.com/advisories/openclaw-arbitrary-file-write-via-symlink-following-in-ssh-sandbox-tar-uploadAdvisory