CYBERHAWK / CVE / CVE-2026-41364

CVE-2026-41364

OpenClaw

HIGH CVSS 8.1 vibe

The flaw

Symlink following vulnerability allows arbitrary file writes via tar uploads.

What to do

Update to version 2026.3.31 or later

▸ Scan my repo for CVE-2026-41364

References

First seen 2026-05-01 · Tracked by PickBits CyberHawk · Weekly CVE digest