CVE-2026-35632

HIGH

OpenClaw < 2026.2.22 - Symlink Traversal via IDENTITY.md appendFile in agents.create/update

Title source: cna
STIX 2.1

Description

OpenClaw through 2026.2.22 contains a symlink traversal vulnerability in agents.create and agents.update handlers that use fs.appendFile on IDENTITY.md without symlink containment checks. Attackers with workspace access can plant symlinks to append attacker-controlled content to arbitrary files, enabling remote code execution via crontab injection or unauthorized access via SSH key manipulation.

Scores

CVSS v3 7.1
EPSS 0.0009
EPSS Percentile 25.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-61
Status published
Products (3)
npm/openclaw 0npm
OpenClaw/OpenClaw
openclaw/openclaw < 2026.2.22
Published Apr 09, 2026
Tracked Since Apr 10, 2026