PT-2026-37006 · Openclaw · Openclaw

·

CVE-2026-42434

·

Published

2026-04-17

·

Updated

2026-05-05

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.4.5 through 2026.4.9
Description Sandboxed agents can escape exec routing by specifying host=node. This allows attackers to bypass sandbox boundaries and route execution to remote nodes instead of the intended sandbox paths.
Recommendations Update to version 2026.4.10 or newer.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42434
GHSA-736R-JWJ6-4W23

Affected Products

Openclaw