GHSA-gq9c-wg68-gwj2: OpenClaw has a path traversal in browser trace/download output paths may allow arbitrary file writes
OpenClaw’s browser control API accepted user-supplied output paths for trace/download files without consistently constraining writes to OpenClaw-managed temporary directories.
References
Code Behaviors & Features
Detect and mitigate GHSA-gq9c-wg68-gwj2 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →