CVE 6 MEDIUM

OpenClaw 2026.3.22 < 2026.4.5 - Symlink Traversal in Remote Marketplace Repository Path Handling_CVE-2026-43570

6 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink paths to access files outside the intended repository directory.

Basic Information

ID CVE-2026-43570
Source VulnCheck
Published May 5, 2026 at 11:25

Affected Product

Vendor OpenClaw
Product OpenClaw
Version 2026.3.22
Affected Versions OpenClaw OpenClaw 2026.3.22

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.