
CVE-2026-32024 OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers to read arbitrary files outside the configured… https://www.cve.org/CVERecord?id=CVE-2026-32024
Post summary
The post announces that OpenClaw versions before 2026.2.22 contain a symlink traversal flaw in avatar handling that can be exploited to read arbitrary files outside the intended directories.
