PT-2026-38245 · Openshell+1 · Openshell+1

·

CVE-2026-44112

·

Published

2026-04-23

·

Updated

2026-05-29

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.22
Description A time-of-check/time-of-use (TOCTOU) race condition exists in OpenShell sandbox filesystem writes. This flaw allows attackers to use symlink swaps during filesystem operations to bypass sandbox restrictions and redirect writes outside the intended local mount root.
Recommendations Update to version 2026.4.22.

Exploit

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08024
CVE-2026-44112
GHSA-6F72-9GXX-98MJ
GHSA-WPPJ-C6MR-83JJ

Affected Products

Openclaw
Openshell