CVE-2026-32013Disclosure(openclaw / openclaw)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and writing files outside the agent workspace. Attackers can exploit symlinked allowlisted files to access arbitrary host files within gateway process permissions, potentially enabling code execution through file overwrite attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-19); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-19: 2Mentions · 2026-03-20: 2Mentions · 2026-03-21: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 103-1903-2003-21
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-192
Disclosure2
2026-03-202
Disclosure2
2026-03-211
Disclosure1
Full discourse5 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    OpenClaw gateway agents have a critical symlink escape vulnerability (CVE-2026-32013) allowing out-of-workspace file read/write. Assess your risk. #infosec #vulnerability #gateway https://www.pulsepatch.io/posts/cve-2026-32013-openclaw-gateway-agents-symlink-escape

    Post summary

    The message announces a new critical symlink escape vulnerability (CVE-2026-32013) in OpenClaw gateway agents, detailing read/write capabilities but offering no PoC, exploit code, evidence of active exploitation, or patch information.

    1001069
    2 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32013 - High OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and writing files outside the agent wor... https://www.thehackerwire.com/vulnerability/CVE-2026-32013/ https://t.co/PZRHUMwV5O

    Post summary

    The post announces CVE‑2026‑32013, a symlink traversal flaw in older OpenClaw versions that lets attackers read/write files via the agents.files methods before version 2026.2.25.

    0001045
    137 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32013 OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and writing fi… https://www.cve.org/CVERecord?id=CVE-2026-32013

    Post summary

    The post announces a symlink traversal flaw in OpenClaw versions before 2026.2.25, describing how it permits reading and writing via specific API methods, with no PoC, exploit, or patch reference.

    00000124
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-32013 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-32013-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-32013 #openclaw #

    Post summary

    An alert for CVE‑2026‑32013 regarding OpenClaw was posted, but the shared content does not supply technical details, exploitation evidence, or remediation guidance.

    0000059
    3.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32013: HIGH] Beware of symlink traversal vulnerability in older OpenClaw versions! Attackers can access files outside the workspace, leading to potential code execution via overwrite attacks.#cve,CVE-2026-32013,#cybersecurity https://cvefind.com/CVE-2026-32013

    Post summary

    A high severity symlink traversal flaw in older OpenClaw versions can allow attackers to access files outside the workspace and potentially execute code via overwrite attacks; no patches or PoC details are offered.

    0000056
    603 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more