#VU125079 Link following in OpenClaw - CVE-2026-32055
Published: April 7, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to write files outside the workspace boundary.
The vulnerability exists due to improper link resolution before file access in the workspace-only path validation logic when processing a guarded workspace path that traverses an in-workspace symlink pointing outside the workspace to a non-existent leaf. A remote user can perform a first write through the crafted path to write files outside the workspace boundary.
The issue occurs during the initial validation window for a non-existent out-of-root symlink target.