
Cloud Vulnerability DB
A community-led vulnerabilities database
In certain workspace-restricted configurations, OpenClaw could follow hardlink aliases inside the workspace that reference files outside the workspace boundary.
By default, tools.fs.workspaceOnly is off. This primarily affects deployments that intentionally enable workspace-only filesystem restrictions (and workspace-only apply_patch checks).
openclaw (npm)2026.2.24<= 2026.2.242026.2.2504d91d0319b82fd4de91ed05e9fc5219ff2ab64e (main)OpenClaw now rejects hardlinked final-file aliases during workspace boundary validation for:
read / write / edit)apply_patch read/write pathsapply_patch, workspace fs tools, and sandbox fs bridge hardlink alias escapes.
OpenClaw thanks @tdjackey for reporting.Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."