6
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink paths to access files outside the intended repository directory.
Basic Information
ID
CVE-2026-43570
Source
VulnCheck
Published
May 5, 2026 at 11:25
Affected Product
Vendor
OpenClaw
Product
OpenClaw
Version
2026.3.22
Affected Versions
OpenClaw OpenClaw 2026.3.22
CWE Classification
References
- github.com /openclaw/openclaw/security/advisories/GHSA-cr8r-7g2h-6wr6
- github.com /openclaw/openclaw/commit/94b0062e90467e1582b47cc971f308457c537f3a
- github.com /openclaw/openclaw/commit/b1dd3ded3589f6fa60ab85b3930a82d538edaeae
- www.vulncheck.com /advisories/openclaw-symlink-traversal-in-remote-marketplace-repository-path-handling