GHSA-xmv6-r34m-62p4: OpenClaw: Sandbox media fallback tmp symlink alias bypass allows host file reads outside sandboxRoot
A sandbox path validation bypass in openclaw allows host file reads outside sandboxRoot via the media path fallback tmp flow when the fallback tmp root is a symlink alias.
References
Code Behaviors & Features
Detect and mitigate GHSA-xmv6-r34m-62p4 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →