Link following in OpenClaw - #VU128765
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to read or modify files outside the workspace boundary.
The vulnerability exists due to improper link resolution before file access in workspace-only filesystem checks when processing in-workspace hardlink aliases that reference files outside the workspace. A remote user can create or use an in-workspace hardlink alias to read or modify files outside the workspace boundary.
This primarily affects deployments that explicitly enable workspace-only filesystem restrictions, including workspace-only apply_patch checks. By default, tools.fs.workspaceOnly is off.