PulsePatch.io@pulsepatchioDisclosure
The message announces a new critical symlink escape vulnerability (CVE-2026-32013) in OpenClaw gateway agents, detailing read/write capabilities but offering no PoC, exploit code, evidence of active exploitation, or patch information.
The Hacker Wire@TheHackerWireDisclosure
The post announces CVE‑2026‑32013, a symlink traversal flaw in older OpenClaw versions that lets attackers read/write files via the agents.files methods before version 2026.2.25.
CVE@CVEnewDisclosure
The post announces a symlink traversal flaw in OpenClaw versions before 2026.2.25, describing how it permits reading and writing via specific API methods, with no PoC, exploit, or patch reference.
RedPacket Security@RedPacketSecDisclosure
An alert for CVE‑2026‑32013 regarding OpenClaw was posted, but the shared content does not supply technical details, exploitation evidence, or remediation guidance.
CVEFind.com@CveFindComDisclosure
A high severity symlink traversal flaw in older OpenClaw versions can allow attackers to access files outside the workspace and potentially execute code via overwrite attacks; no patches or PoC details are offered.