Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

AI SAST Finding: Path Traversal in OpenClaw via LLM Guardrail Bypass

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Peyton Kennedy
Word Count
2,041
Company Posts That Month
16
Language
English
Hacker News Points
-
Post removed?
No
Summary

The final post in a series on Endor Labs' AI SAST engine explores a high-severity path traversal vulnerability (GHSA-r5fq-947m-xm57) found in OpenClaw's apply_patch tool, which allows arbitrary file writes and deletions outside the workspace due to unguarded file system operations. The vulnerability is particularly significant because it is only exploitable through large language model (LLM)-mediated tool execution, where fabricated conversation history can bypass the LLM's safety guardrails. The AI SAST engine identified this vulnerability by tracing data flows from attacker-controlled inputs to unguarded file operations, but the LLM guardrail bypass was discovered during exploit validation. The vulnerability affects versions of OpenClaw up to 2026.2.13, and a fix was implemented in version 2026.2.14 to ensure workspace containment. The post underscores the risks of relying on LLM safety trainings as security boundaries, highlighting the probabilistic nature of LLM behavior and the attack surface created by conversation history.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
LLM 18 5,138 781 181 +34%
OpenClaw 17 1,172 87 30 +176%
Observability 3 2,816 550 145 +34%
AI Agents 1 3,583 743 199 -1%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.