CVE-2026-19008: mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following
A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component applypatch Tool. Such manipulation leads to link following. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19008?
CVE-2026-19008 has a medium severity rating of 6.3.
How do I fix CVE-2026-19008?
To fix CVE-2026-19008, update the mf-yang openclaw-cn to version 0.2.2 or later.
What components are affected by CVE-2026-19008?
CVE-2026-19008 affects the apply_patch Tool in the mf-yang openclaw-cn software.
Can CVE-2026-19008 be exploited remotely?
Yes, CVE-2026-19008 can be exploited remotely.
What type of attack is associated with CVE-2026-19008?
CVE-2026-19008 is associated with link following manipulation attacks.