CVE-2026-43570 PUBLISHED

OpenClaw 2026.3.22 < 2026.4.5 - Symlink Traversal in Remote Marketplace Repository Path Handling

Assigner: VulnCheck
Reserved: 01.05.2026 Published: 05.05.2026 Updated: 05.05.2026

OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink paths to access files outside the intended repository directory.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6

Product Status

Vendor OpenClaw
Product OpenClaw
Versions Default: unaffected
  • affected from 2026.3.22 to 2026.4.5 (excl.)
  • Version 2026.4.5 is unaffected

Credits

  • zsx (@zsxsoft) reporter
  • KeenSecurityLab coordinator

References

Problem Types

  • CWE-61 UNIX Symbolic Link (Symlink) Following CWE