A path-confinement bypass in browser output handling allowed writes outside intended roots in openclaw versions up to and including 2026.3.1.
The fix unifies root-bound, file-descriptor-verified write semantics and canonical path-boundary validation across browser output and related install/skills write paths.
openclaw (npm)2026.3.1<= 2026.3.12026.3.2 (released)104d32bb64cdf19d5e77f70553a511a2ae90ad1c{
"cwe_ids": [
"CWE-367",
"CWE-59"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-03T21:20:01Z",
"nvd_published_at": null,
"severity": "MODERATE"
}