{"id":"CVE-2026-45224","summary":"Crabbox \u003c 0.9.0 Path Traversal via Islo Provider Workspace Resolution","details":"Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allows attackers to supply absolute or relative paths that resolve outside the intended /workspace directory. Attackers can craft a malicious .crabbox.yaml or crabbox.yaml file with traversal sequences to cause arbitrary file deletion and overwrite when sync.delete is enabled, as the workspace preparation logic executes rm -rf and mkdir -p operations on the resolved path without proper validation.","aliases":["GHSA-3cjv-h753-qf7h","GO-2026-5079"],"modified":"2026-08-04T11:51:03.852891397Z","published":"2026-05-11T18:12:51.252Z","related":["openSUSE-SU-2026:21483-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45224.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45224.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/crabbox/releases/tag/v0.9.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45224"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/crabbox-path-traversal-via-islo-provider-workspace-resolution"},{"type":"REPORT","url":"https://github.com/openclaw/crabbox/pull/65"},{"type":"FIX","url":"https://github.com/openclaw/crabbox/commit/6b07193fb5670aac315ea47215651c67b8127868"},{"type":"PACKAGE","url":"https://github.com/openclaw/crabbox"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openclaw/crabbox","events":[{"introduced":"0"},{"fixed":"b5a3561fa77f8ebdce046bf54841283e96df05c0"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.9.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v0.8.0","v0.7.0","v0.6.0","v0.5.1","v0.5.0","v0.4.0","v0.3.1","v0.3.0","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45224.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"}]}