LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-31990

openclaw · openclaw

Published
CVSS6.1
Severitymedium
WeaknessCWE-59
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Description

OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to validate destination symlinks during media staging, allowing writes to follow symlinks outside the sandbox workspace. Attackers can exploit this by placing symlinks in the media/inbound directory to overwrite arbitrary files on the host system outside sandbox boundaries.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-31990

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-31990.