Link following in OpenClaw - CVE-2026-41397

 

Link following in OpenClaw - CVE-2026-41397

Published: April 30, 2026


Vulnerability identifier: #VU128626
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41397
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escape the sandbox and access unintended files.

The vulnerability exists due to improper link resolution before file access in the Mirror Sync file synchronization feature when processing synced files and symlinks. A remote attacker can upload or transfer a specially crafted symlink to escape the sandbox and access unintended files.


Affected software

OpenClaw

How to mitigate CVE-2026-41397

Install security update from vendor's website.

OpenClaw - update to 2026.3.31

External References

Related Security Bulletins