PT-2026-29235 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-31
·
Updated
2026-03-31
·
CVE-2026-32988
CVSS v3.1
7.5
High
| AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H |
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path before the final guarded replace step executes.
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw