CVE-2026-27485 | OpenClaw up to 2026.2.18 package_skill.py symlink (GHSA-r6h2-5gqq-v5v6)
A vulnerability, which was classified as critical, was found in OpenClaw up to 2026.2.18. This affects an unknown function of the file skills/skill-creator/scripts/package_skill.py. Such manipulation leads to symlink following.
This vulnerability is referenced as CVE-2026-27485. The attack can only be performed from a local environment. No exploit is available.
You should upgrade the affected component.