CVE-2026-43570

medium
Published 2026-05-05 · Modified 2026-05-08
CVSS v3
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v2
VIR risk
6.5

Description

OpenClaw contains a symlink traversal vulnerability

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/security/advisories/GHSA-cr8r-7g2h-6wr6

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/commit/b1dd3ded3589f6fa60ab85b3930a82d538edaeae

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/commit/94b0062e90467e1582b47cc971f308457c537f3a

Package impact

EcosystemPackageVulnerableFixed
npm npmopenclaw>=2026.3.22,<2026.4.52026.4.5
npm NPMopenclaw>= 2026.3.22, < 2026.4.52026.4.5

Application impact

VendorProductVersionsFixed
openclawopenclaw{"startIncluding":"2026.3.22","endExcluding":"2026.4.5"}2026.4.5

References

CWEs

CWE-61

Verify integrity in audit chain (admin only). AS-IS.