Untriaged
Permalink
CVE-2026-33574
6.2 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
OpenClaw < 2026.3.8 - Path Traversal via Tools Root Rebinding in Skills Download
OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the tools root lexically but reuses the mutable path during archive download and copy operations. A local attacker can rebind the tools-root path between validation and final write to redirect the installer outside the intended tools directory.
References
-
GitHub Security Advisory (GHSA-vhwf-4x96-vqx2) third-party-advisory
-
Patch Commit patch
Affected products
OpenClaw
- ==2026.3.8
- <2026.3.8
Package maintainers
-
@chrisportela Chris Portela <chris@chrisportela.com>