Description
OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.
Severity (CVSS)
| Base score | 7.6 |
|---|---|
| Severity | High |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-59 — Improper Link Resolution Before File Access ('Link Following')
- CWE-367 — Time-of-check Time-of-use (TOCTOU) Race Condition
Affected products
| Vendor | Product | Versions |
|---|---|---|
| OpenClaw | OpenClaw | 0 to <2026.6.9; 2026.6.9 |
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-m38g-vpwj-mpg9 (vendor-advisory)
- https://www.vulncheck.com/advisories/openclaw-symlink-following-via-mirror-sync (third-party-advisory)
Generated from the official CVE List on 14 Jul 2026 07:01 UTC.