PT-2026-28448 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-29
·
Updated
2026-03-29
·
CVE-2026-32918
CVSS v3.1
8.4
High
| AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.11
Description
The software contains a session sandbox escape issue within the
session status tool. This allows sandboxed subagents to access session state belonging to parent or sibling sessions. An attacker can provide arbitrary sessionKey values to read or modify session data outside of their designated sandbox, potentially including persisted model overrides.Recommendations
Update to version 2026.3.11 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw