CVE-2026-27485General(openclaw / openclaw)

LOWCVSS 4.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, skills/skill-creator/scripts/package_skill.py (a local helper script used when authors package skills) previously followed symlinks while building .skill archives. If an author runs this script on a crafted local skill directory containing symlinks to files outside the skill root, the resulting archive can include unintended file contents. If exploited, this vulnerability can lead to potential unintentional disclosure of local files from the packaging machine into a generated .skill artifact, but requires local execution of the packaging script on attacker-controlled skill contents. This issue has been fixed in version 2026.2.18.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-01: 1Technical Details · 2026-03-01: 103-01
Signal classification1 categories
General
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • Coyote Security Scanner@CoyoteSecure
    General

    Okay, Sunday morning dev session complete, here's what we built this morning 💪🐺 Expand OpenClaw security coverage by implementing ten new CVE checks in the existing version and precondition analyzer model, with full test and doc updates. Added CVE checks: - CVE-2026-26324 (SSRF IPv4-mapped IPv6 guard bypass) - CVE-2026-26325 (http://system.run rawCommand/argv mismatch bypass) - CVE-2026-26316 (BlueBubbles webhook auth bypass) - CVE-2026-26326 (skills.status secret disclosure) - CVE-2026-27003 (Telegram token log exposure) - CVE-2026-27009 (Control UI stored XSS) - CVE-2026-26320 (deep-link prompt truncation/social engineering) - CVE-2026-27487 (macOS keychain refresh command injection) - CVE-2026-27486 (cleanup cross-process termination) - CVE-2026-27485 (skill packager symlink file disclosure) Implementation details: - Extend `_CVE_FIX_VERSIONS` with new fixed-version thresholds. - Add recursive config string/pattern helpers for indicator detection. - Add all new checks to `OpenClawSecurityAnalyzer.analyze(...)`. - Extend `_build_cve_check(...)` with optional `min_affected_version` handling for range-sensitive CVEs (used by CVE-2026-26320). - Keep existing status semantics: VULNERABLE/WARNING/SAFE/UNKNOWN. Tests: - Expand `tests/test_openclaw_security.py` to validate: - new CVE presence - version-threshold behavior - patched-version risky-config WARNING behavior - UNKNOWN behavior for all tracked CVEs Docs: - Update README OpenClaw coverage from 5 to 15 CVEs. - Add all new CVEs to "OpenClaw CVEs Covered" and "Checks Performed" tables. - Refresh OpenClaw example summary text. - Rewrite http://OpenClawCVEs.md with full 15-CVE coverage and per-check logic. Validation: - `python3 -m unittest tests/test_openclaw_security.py` (pass) - `python3 -m unittest discover -s tests` (pass, 31 tests)

    Post summary

    The post announces the addition of 10 new CVE checks to OpenClaw’s security analyzer, detailing the CVEs and implementation updates, but does not mention PoC, exploits, active use, patches, or false positives.

    20010192
    225 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more