Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
OpenClaw: Attackers Can Escape From the Safe Sandbox
GHSA-9p3r-hh9g-5cmg
Summary
A security issue in OpenClaw allows attackers to escape from a safe area of the system and access sensitive information. This affects users who are running version 2026.3.28 or earlier of the OpenClaw package. To fix this, update to version 2026.3.31 or later.
What to do
- Update openclaw to version 2026.3.31.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| – | openclaw | <= 2026.3.28 | 2026.3.31 |
Original title
OpenClaw: Sandbox escape via TOCTOU race in remote FS bridge readFile
Original description
## Summary
Sandbox escape via TOCTOU race in remote FS bridge readFile
## Current Maintainer Triage
- Normalized severity: critical
- Assessment: v2026.3.28 remote sandbox reads still do path-check then separate file read, so the TOCTOU sandbox escape remains present in the latest shipped tag.
## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `<=2026.3.28`
- Patched versions: `>= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`
## Fix Commit(s)
- `121870a08583033ed6a0ed73d9ffea32991252bb` — 2026-03-31T09:55:51+09:00
OpenClaw thanks @AntAISecurityLab for reporting.
Sandbox escape via TOCTOU race in remote FS bridge readFile
## Current Maintainer Triage
- Normalized severity: critical
- Assessment: v2026.3.28 remote sandbox reads still do path-check then separate file read, so the TOCTOU sandbox escape remains present in the latest shipped tag.
## Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published npm version: `2026.3.31`
- Vulnerable version range: `<=2026.3.28`
- Patched versions: `>= 2026.3.31`
- First stable tag containing the fix: `v2026.3.31`
## Fix Commit(s)
- `121870a08583033ed6a0ed73d9ffea32991252bb` — 2026-03-31T09:55:51+09:00
OpenClaw thanks @AntAISecurityLab for reporting.
ghsa CVSS4.0
9.4
Vulnerability type
CWE-367
Published: 3 Apr 2026 · Updated: 3 Apr 2026 · First seen: 3 Apr 2026