GHSA-5799-3xg7-rfrv: Duplicate Advisory: OpenClaw: SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host
(updated )
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-fv94-qvg8-xqpw. This link is maintained to preserve external references.
Original Description
OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sandbox and overwrite files on the remote host.
References
- github.com/advisories/GHSA-5799-3xg7-rfrv
- github.com/openclaw/openclaw/commit/3d5af14984ac1976c747a8e11581d697bd0829dc
- github.com/openclaw/openclaw/security/advisories/GHSA-fv94-qvg8-xqpw
- nvd.nist.gov/vuln/detail/CVE-2026-41364
- www.vulncheck.com/advisories/openclaw-arbitrary-file-write-via-symlink-following-in-ssh-sandbox-tar-upload
Code Behaviors & Features
Detect and mitigate GHSA-5799-3xg7-rfrv with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →