Impact
OpenClaw versions prior to 2026.6.9 contain a vulnerability in the mirror sync feature that follows symbolic links, exploiting directory traversal (CWE‑59) and untrusted symbolic‑link handling (CWE‑367). This flaw allows callers with lower trust to manipulate symlink parents and perform operations that are normally protected by stronger authorization checks. The resulting impact is a breach of the intended access controls, enabling unauthorized users to execute privileged actions against the system.
Affected Systems
The vulnerability affects the OpenClaw product from the OpenClaw vendor, specifically any installation of OpenClaw older than version 2026.6.9. No other products or versions are listed as impacted in the available data.
Risk and Exploitability
The CVSS score of 7.6 classifies the issue as high severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Attackers are likely to exploit the flaw by invoking the mirror sync endpoint over the network, a remote attack vector that relies on the feature being enabled and accessible. Based on the description, it is inferred that the attack path involves remote interaction with the mirror sync service; the exact network‑access requirements are not explicitly stated in the data.
OpenCVE Enrichment