CVE-2026-32007
OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental applypatch tool that allows attackers with sandbox access to modify files outside the workspace directory by exploiting inconsistent enforcement of workspace-only checks on mounted paths. Attackers can use applypatch operations on writable mounts outside the workspace root to access and modify arbitrary files on the system.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://www.vulncheck.com/advisories/openclaw-sandbox-bypass-in-apply-patch-tool-via-workspace-only-check-bypass, https://github.com/openclaw/openclaw/security/advisories/GHSA-h9xm-j4qg-fvpg, https://github.com/openclaw/openclaw/commit/6634030be31e1a1842967df046c2f2e47490e6bf
