PT-2026-26384 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-04
·
Updated
2026-03-20
·
CVE-2026-32002
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.23
Description
The sandboxed image tool does not enforce
tools.fs.workspaceOnly restrictions on mounted sandbox paths, allowing attackers to read files outside the designated workspace. Attackers can load restricted mounted images and exfiltrate them through vision model provider requests, bypassing sandbox confidentiality controls. The workspaceOnly setting was enforced in sandbox file tools and apply patch, but not propagated to the image sandbox path resolution.Recommendations
OpenClaw versions prior to 2026.2.23 should be updated to version 2026.2.23 or later.
Fix
Information Disclosure
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw