GHSA-x82f-27x3-q89c: OpenClaw's TOCTOU symlink race in writeFileWithinRoot could create or truncate files outside root boundaries
A symlink-retarget TOCTOU race in writeFileWithinRoot could point an attacker-controlled path alias outside the configured root between resolution and write operations.
References
Code Behaviors & Features
Detect and mitigate GHSA-x82f-27x3-q89c with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →