In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabilities in an interactive lesson.
Start learningUpgrade openclaw to version 2026.2.25 or higher.
openclaw is a 🦞 OpenClaw — Personal AI Assistant
Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition via system.run when a mutable symlink is used as the cwd target between approval and execution. An attacker can execute commands in an unintended directory by altering the symlink after approval but before execution.