Impact
The vulnerability resides in the apply_patch tool of mf-yang's openclaw-cn, specifically in the assertNoSymlinkEscape function in sandbox-paths.ts. The flaw allows an attacker to craft paths containing symbolic links that traverse outside the intended sandbox, resulting in link following and unauthorized file access or modification. The vulnerability maps to CWE‑59 and can enable data disclosure or integrity compromise.
Affected Systems
Affected product: mf-yang:openclaw-cn (openclaw‑cn), versions up to and including 0.2.1. No further version information is provided. Users running 0.2.1 or earlier must watch for updates.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV. It is remotely accessible; public proof‑of‑concept exploits exist. With no current vendor patch or workaround, the risk remains until mitigation steps are applied.
OpenCVE Enrichment