OpenClaw Symlink Traversal Vulnerability in Avatar Handling

Vulnerability

A symlink traversal vulnerability has been identified in OpenClaw versions prior to 2026.2.22. This vulnerability allows remote attackers to read arbitrary files outside the designated workspace boundary by exploiting avatar handling through gateway surfaces. The issue arises because the avatar resolution process can follow symlinks and access local files available to the OpenClaw process, potentially leading to unauthorized disclosure of sensitive information.

Impact

Exploitation of this vulnerability could result in the unauthorized disclosure of local files accessible to the OpenClaw process, bypassing workspace boundaries and exposing sensitive information.

Reproduction

To reproduce this vulnerability, create a symbolic link in the avatar workspace that points to a file outside the workspace boundary. Then, upload this linked file as an avatar. When the avatar is requested through the gateway, the file outside the workspace will be read and returned, demonstrating the symlink traversal.

Remediation

Users can update to OpenClaw version 2026.2.22 or later, where this vulnerability has been patched.

Added: Mar 19, 2026, 10:38 PM
Updated: Mar 19, 2026, 10:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.2
remediation
0.0
relevance
4.1
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.