Link following in OpenClaw - CVE-2026-32054
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to overwrite arbitrary files.
The vulnerability exists due to improper link resolution before file access in browser trace/download output path handling when processing attacker-influenced output paths in the managed temp root. A local user can create a symlink path that escapes the temp root to overwrite arbitrary files.
Exploitation requires a relevant local foothold and the ability to influence output paths.