PT-2026-37006 · Openclaw · Openclaw

Keensecuritylab

+1

·

Published

2026-04-17

·

Updated

2026-05-05

·

CVE-2026-42434

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.4.5 through 2026.4.9
Description Sandboxed agents can escape exec routing by specifying host=node. This allows attackers to bypass sandbox boundaries and route execution to remote nodes instead of the intended sandbox paths.
Recommendations Update to version 2026.4.10 or newer.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-42434
GHSA-736R-JWJ6-4W23

Affected Products

Openclaw