Medium severity5.3NVD Advisory· Published Mar 18, 2026· Updated Jun 17, 2026
CVE-2026-22180
CVE-2026-22180
Description
OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allows writes outside intended root directories. Attackers can exploit insufficient canonical path-boundary validation in file write operations to escape root-bound restrictions and write files to arbitrary locations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openclawnpm | < 2026.3.2 | 2026.3.2 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/openclaw/openclaw/commit/104d32bb64cdf19d5e77f70553a511a2ae90ad1cnvdPatchWEB
- github.com/advisories/GHSA-3pxq-f3cp-jmxpghsaADVISORY
- github.com/openclaw/openclaw/security/advisories/GHSA-3pxq-f3cp-jmxpnvdVendor AdvisoryWEB
- www.vulncheck.com/advisories/openclaw-path-confinement-bypass-in-browser-output-and-file-write-operationsnvdThird Party Advisory
News mentions
0No linked articles in our index yet.