CVE-2026-19008: A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component ap
A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. Such manipulation leads to link following. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-19008
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-190080.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19008 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for mf-yang openclaw-cn
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-19007: A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects …nvd · 2026-08-06
- mediumCVE-2026-19006: A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the…nvd · 2026-08-06
- mediumCVE-2026-17458: A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickV…nvd · 2026-07-26
- mediumCVE-2026-17457: A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is t…nvd · 2026-07-26
More from NVD Recent CVEs
- highCVE-2026-19190: A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part …2026-08-07
- unknownCVE-2026-49746: Software installed and run as a non-privileged user may conduct improper GPU system calls to c…2026-08-07
- unknownCVE-2026-45204: Software installed and run as a non-privileged user may conduct improper GPU system calls to t…2026-08-07
- unknownCVE-2026-45198: Kernel software from a non-secure operating system on a platform with Trusted Execution Enviro…2026-08-07
- highCVE-2026-19189: A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue …2026-08-07