GHSA-mgrq-9f93-wpp5: OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf
openclaw had a workspace boundary bypass in workspace-only path validation: when an in-workspace symlink pointed outside the workspace to a non-existent leaf, the first write could pass validation and create the file outside the workspace.
References
Code Behaviors & Features
Detect and mitigate GHSA-mgrq-9f93-wpp5 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →