#VU125118 Link following in OpenClaw - CVE-2026-31990
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to overwrite files outside the sandbox workspace.
The vulnerability exists due to improper link resolution before file access in stageSandboxMedia when handling inbound files during media staging. A remote attacker can place or leverage a symlink in the destination path to overwrite files outside the sandbox workspace.
The issue affects destination writes under media/inbound that follow symlinks outside the intended sandbox workspace boundary.