GHSA-36h3-7c54-j27r

Suggest an improvement
Source
https://github.com/advisories/GHSA-36h3-7c54-j27r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-36h3-7c54-j27r/GHSA-36h3-7c54-j27r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-36h3-7c54-j27r
Aliases
Downstream
Published
2026-03-02T22:18:07Z
Modified
2026-03-27T21:11:21Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw has browser trace/download path symlink escape in temp output handling
Details

Summary

Browser trace/download output path handling allowed symlink-root and symlink-parent escapes from the managed temp root.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published npm version: 2026.2.24
  • Affected versions: <= 2026.2.24
  • Planned patched release: 2026.2.25

Impact

An attacker with relevant local foothold and ability to influence output paths could route writes outside the intended temp root via symlink traversal, leading to arbitrary file overwrite.

Fix Commit(s)

  • 496a76c03ba85e15ea715e5a583e498ae04d36e3

Release Process Note

patched_versions is pre-set to the release (2026.2.25) so once npm 2026.2.25 is published, the advisory is published.

OpenClaw thanks @tdjackey for reporting.

Database specific
{
    "cwe_ids":  [
        "CWE-22",
        "CWE-59"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-02T22:18:07Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.2.25

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-36h3-7c54-j27r/GHSA-36h3-7c54-j27r.json"