


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers …
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 19:01:18
Source:
nvd.nist.gov
Network Infrastructure, Security Tools
OpenClaw versions before 2026.3.31 contain a symlink following vulnerability in the SSH sandbox tar upload functionality. Remote attackers can exploit this vulnerability by uploading specially crafted tar archives containing symlinks. The vulnerability allows attackers to escape the sandbox environment and write arbitrary files on the remote host. This represents a significant security risk as it bypasses sandbox protections and enables unauthorized file system access. The issue has been addressed in version 2026.3.31 and later releases.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41364
https://github.com/openclaw/openclaw/commit/3d5af14984ac1976c747a8e11581d697bd0829dc
https://github.com/openclaw/openclaw/security/advisories/GHSA-fv94-qvg8-xqpw
https://www.vulncheck.com/advisories/openclaw-arbitrary-file-write-via-symlink-following-in-ssh-sandbox-tar-upload
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
