Incorrect Behavior Order: Validate Before Canonicalize in OpenClaw - #VU149038
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect behavior order: validate before canonicalize in the tools.fs.workspaceOnly Unicode filename fallback when retrying a missing path within the configured workspace. A remote user can request access to a known file outside the configured workspace boundary to disclose sensitive information.
Exploitation requires distinct canonically equivalent sibling directory names on the filesystem and knowledge of a useful target path; it does not rely on symlinks or hardlinks.