OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink paths to access files outside the intended...
Full CISO analysis pending enrichment.
Affected Systems
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| openclaw | npm | >= 2026.3.22, < 2026.4.5 | 2026.4.5 |
Do you use openclaw? You're affected.
Severity & Risk
Attack Surface
Recommended Action
Patch available
Update openclaw to version 2026.4.5
Compliance Impact
Compliance analysis pending. Sign in for full compliance mapping when available.
Frequently Asked Questions
What is CVE-2026-43570?
OpenClaw contains a symlink traversal vulnerability
Is CVE-2026-43570 actively exploited?
No confirmed active exploitation of CVE-2026-43570 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-43570?
Update to patched version: openclaw 2026.4.5.
What is the CVSS score for CVE-2026-43570?
CVE-2026-43570 has a CVSS v3.1 base score of 6.5 (MEDIUM). The EPSS exploitation probability is 0.04%.
Technical Details
NVD Description
OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink paths to access files outside the intended repository directory.
Weaknesses (CWE)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N References
- github.com/advisories/GHSA-35mw-5vvr-vrxc
- github.com/openclaw/openclaw/commit/94b0062e90467e1582b47cc971f308457c537f3a
- github.com/openclaw/openclaw/commit/b1dd3ded3589f6fa60ab85b3930a82d538edaeae
- github.com/openclaw/openclaw/security/advisories/GHSA-cr8r-7g2h-6wr6
- nvd.nist.gov/vuln/detail/CVE-2026-43570
- vulncheck.com/advisories/openclaw-symlink-traversal-in-remote-marketplace-repository-path-handling
Timeline
Related Vulnerabilities
CVE-2026-30741 9.8 OpenClaw: RCE via request-side prompt injection
Same package: openclaw CVE-2026-28451 9.3 OpenClaw: SSRF via Feishu extension exposes internal services
Same package: openclaw GHSA-cwj3-vqpp-pmxr 8.8 Analysis pending
Same package: openclaw GHSA-m3mh-3mpg-37hw 8.6 OpenClaw: .npmrc hijack enables RCE on plugin install
Same package: openclaw CVE-2026-27001 7.8 OpenClaw: prompt injection via unsanitized workspace path
Same package: openclaw
AI Threat Alert