Description

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.

Severity (CVSS)

Base score7.6
SeverityHigh
VersionCVSS 4.0
VectorCVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Provided byCNA

Weaknesses

  • CWE-59 — Improper Link Resolution Before File Access ('Link Following')
  • CWE-367 — Time-of-check Time-of-use (TOCTOU) Race Condition

Affected products

VendorProductVersions
OpenClawOpenClaw0 to <2026.6.9; 2026.6.9

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 14 Jul 2026 07:01 UTC.