CVE-2026-32060
OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in applypatch that allows attackers to write or delete files outside the configured workspace directory. When applypatch is enabled without filesystem sandbox containment, attackers can exploit crafted paths including directory traversal sequences or absolute paths to escape workspace boundaries and modify arbitrary files.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://www.vulncheck.com/advisories/openclaw-path-traversal-in-apply-patch-via-crafted-paths, https://github.com/openclaw/openclaw/commit/5544646a09c0121fca7d7093812dc2de8437c7f1, https://github.com/openclaw/openclaw/security/advisories/GHSA-r5fq-947m-xm57
