Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade openclaw to version 2026.3.24-beta.1 or higher.
openclaw is a 🦞 OpenClaw — Personal AI Assistant
Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following via the agents.create and agents.update processes. An attacker can append arbitrary content to files outside the intended workspace by planting a symlink at the IDENTITY.md path, which is then followed by the file append operation. This enables modification of sensitive system or user files with attacker-controlled data.