#VU125123 Link following in OpenClaw - CVE-2026-22180
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a local user to write files outside intended roots.
The vulnerability exists due to improper link resolution before file access in browser output handling and related write paths when processing path-boundary flows. A local user can use a crafted path or symlink rebind to write files outside intended roots.
The issue involves browser output as well as related install and skills write paths.