Link following in OpenClaw - CVE-2026-32024
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper link resolution before file access in avatar handling when resolving local avatar paths. A local user can create a symlink path that resolves outside the configured workspace boundary to disclose sensitive information.
Only files readable by the OpenClaw process can be exposed via gateway avatar surfaces.