GHSA-35mw-5vvr-vrxc

Suggest an improvement
Source
https://github.com/advisories/GHSA-35mw-5vvr-vrxc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-35mw-5vvr-vrxc/GHSA-35mw-5vvr-vrxc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-35mw-5vvr-vrxc
Aliases
  • CVE-2026-43570
Downstream
Published
2026-05-05T12:31:39Z
Modified
2026-05-08T20:26:40.357628Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw contains a symlink traversal vulnerability
Details

OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink paths to access files outside the intended repository directory.

Database specific
{
    "github_reviewed_at": "2026-05-08T20:04:46Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-61"
    ],
    "nvd_published_at": "2026-05-05T12:16:20Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
2026.3.22
Fixed
2026.4.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-35mw-5vvr-vrxc/GHSA-35mw-5vvr-vrxc.json"