CVE-2026-19008 | mf-yang openclaw-cn up to 0.2.1 apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following (565/566)
A vulnerability was found in mf-yang openclaw-cn up to 0.2.1 and classified as critical. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. Such manipulation leads to link following.
This vulnerability is referenced as CVE-2026-19008. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.