GHSA-jxrq-8fm4-9p58

Suggest an improvement
Source
https://github.com/advisories/GHSA-jxrq-8fm4-9p58
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-jxrq-8fm4-9p58/GHSA-jxrq-8fm4-9p58.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jxrq-8fm4-9p58
Downstream
Published
2026-03-03T23:09:31Z
Modified
2026-03-04T15:15:55Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw: Zip extraction symlink traversal could write outside destination
Details

Summary

A path confinement bypass in OpenClaw ZIP extraction allowed writes outside the intended destination when a pre-existing symlink was present under the extraction root.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published npm version at triage time: 2026.2.21-2
  • Affected versions: <= 2026.2.21-2
  • Planned patched version for next release: 2026.2.22

Technical Details

The vulnerable path was in src/infra/archive.ts ZIP extraction logic. Output-path checks were lexical, but writes could still traverse an existing symlink in destination path segments.

The fix blocks this by:

  • rejecting symlink traversal in destination path segments,
  • validating resolved destination paths remain inside the extraction root,
  • using no-follow file opens for ZIP output writes where supported,
  • adding a regression test for pre-seeded destination symlink traversal.

Impact

  • Type: Arbitrary file write outside extraction root via symlink traversal during ZIP extraction.
  • Preconditions: attacker-controlled archive extraction plus pre-existing symlink in destination path.

Fix Commit(s)

  • 4b226b74f5fd3b106a83a6347fd404172e2fd246

Release Process Note

Patched version is pre-set to the planned next release (2026.2.22). Once npm release 2026.2.22 is published, the advisory can be published without further field edits.

OpenClaw thanks @tdjackey for reporting.

Database specific
{
    "cwe_ids":  [
        "CWE-59"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-03T23:09:31Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.2.22

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-jxrq-8fm4-9p58/GHSA-jxrq-8fm4-9p58.json"