OpenClaw Symlink Following Vulnerability in Skill Packaging Script

Vulnerability

A vulnerability exists in OpenClaw versions through 2026.2.17, where the skill packaging script followed symlinks, potentially leading to unintended file inclusion in .skill archives. This could result in accidental disclosure of local files from the user's machine into the packaged skill, but only if the script is run on a skill directory controlled by an attacker.

Impact

Exploitation of this vulnerability could cause unintentional inclusion of sensitive local files in a .skill package, which could then be distributed or used inappropriately.

Reproduction

To reproduce this vulnerability, create a local skill directory that includes symlinks to files outside the skill root. Then, run the 'package_skill' script from the 'skills/skill-creator/scripts' directory. The script will follow the symlinks and include the external file contents in the resulting .skill archive.

Remediation

This vulnerability has been addressed in OpenClaw version 2026.2.18, which prevents symlink following during the packaging process. Users should update to this version.

Added: Feb 21, 2026, 10:27 AM
Updated: Feb 21, 2026, 10:27 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.6
remediation
0.0
relevance
3.3
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.