CVE-2026-41364Disclosure(openclaw / openclaw)

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sandbox and overwrite files on the remote host.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-28); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-28: 3Mentions · 2026-04-29: 2Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-28: 2Technical Details · 2026-04-29: 204-2804-29
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-283
Disclosure3
2026-04-292
Disclosure2
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-41364 OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can ex… https://www.cve.org/CVERecord?id=CVE-2026-41364

    Post summary

    The post announces a symlink following flaw in OpenClaw’s SSH sandbox tar upload that permits remote file writes, providing technical details but no PoC, exploit code, or patch information.

    00010253
    57.3K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: High Arbitrary File Write & Privilege Escalation in OpenClaw. #CVE-2026-41364 CVSS: 8.1 & #CVE-2026-41371 CVSS: 8.5. Symlink abuse in SSH sandbox tar upload may overwrite files, while auth callers can trigger admin-only session resets! #Patch #Patch #Patch

    Post summary

    The post warns of high‑severity arbitrary file write and privilege escalation bugs in OpenClaw (CVE-2026-41364 and CVE-2026-41371) with CVSS scores 8.1 and 8.5, notes symlink abuse during SSH sandbox tar uploads, and indicates patches are available.

    01000154
    7.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-41364 OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can ex… https://www.cve.org/CVERecord?id=CVE-2026-41364 ----- Traducción: CVE-2026-41364 Ope… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-41364, describing its remote file write flaw, but does not provide a PoC, exploit, or mitigation.

    0000037
    74 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41364 Symlink Following Vulnerability in OpenClaw SSH Sandbox Tar Upload Before 2026.3.31 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41364

    Post summary

    The post announces a symlink following vulnerability in OpenClaw SSH Sandbox affecting uploads prior to version 2026.3.31.

    0000049
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-41364 📊 Severity: 8.1 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41364 #CVE-2026-41364 #CVE #High #CyberSecurity #InfoSec https://t.co/aF5nUi6TmK

    Post summary

    The tweet announces the CVE‑2026‑41364 vulnerability with a high severity rating, linking to the NIST NVD page, but provides no further technical, exploit, or remediation details.

    0000043
    142 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more