PT-2026-33863 · Openclaw · Openclaw

Antaisecuritylab

·

Published

2026-04-03

·

Updated

2026-04-21

·

CVE-2026-41296

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description A time-of-check-time-of-use (TOCTOU) race condition exists in the remote filesystem bridge readFile() function. This occurs because path validation and file read operations are performed separately, allowing attackers to bypass sandbox restrictions and read arbitrary files, resulting in a sandbox escape.
Recommendations Update to version 2026.3.31 or later.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41296
GHSA-9P3R-HH9G-5CMG

Affected Products

Openclaw