SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.313d5af14984ac1976c747a8e11581d697bd0829dc — 2026-03-31T19:56:45+09:00OpenClaw thanks @AntAISecurityLab for reporting.
{
"github_reviewed": true,
"github_reviewed_at": "2026-04-02T21:23:32Z",
"cwe_ids": [
"CWE-59",
"CWE-61"
],
"severity": "HIGH",
"nvd_published_at": null
}