CVE-2026-19008
Published: Thu, 06 Aug 2026 08:16
Summary
A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. Such
Details
A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. Such manipulation leads to link following. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Are YOU affected by CVE-2026-19008?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether CVE-2026-19008 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
References
- https://github.com/mf-yang/openclaw-cn/
- https://github.com/mf-yang/openclaw-cn/issues/565
- https://github.com/mf-yang/openclaw-cn/issues/566
- https://vuldb.com/cve/CVE-2026-19008
- https://vuldb.com/submit/862644
- https://vuldb.com/submit/862645
- https://vuldb.com/vuln/386391
- https://vuldb.com/vuln/386391/cti
StackPatch runs this match against YOUR installed packages every hour
Free (3 servers) / from $9/mo (14-day free trial) / Solo $9/mo / Pro $29/mo / Team $79/mo. Indie pricing.