CVE-2026-31990 is a high-severity symlink traversal vulnerability affecting OpenClaw versions prior to 2026.3.2. The flaw exists in the stageSandboxMedia function, which fails to validate destination symlinks, allowing an attacker to write outside the sandbox workspace. This permits a local attacker with low privileges to overwrite arbitrary files on the host system, resulting in high integrity and availability impacts (CVSS 7.1). There is currently no evidence of active exploitation, no public exploit modules are available, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.2CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.2CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.