PT-2026-38245 · Openclaw+1 · Openclaw+1

Vladimir Tokarev

·

Published

2026-05-04

·

Updated

2026-05-29

·

CVE-2026-44112

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.22
Description A time-of-check/time-of-use (TOCTOU) race condition exists in OpenShell sandbox filesystem writes. This flaw allows attackers to use symlink swaps during filesystem operations to bypass sandbox restrictions and redirect writes outside the intended local mount root.
Recommendations Update to version 2026.4.22.

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2026-44112
GHSA-6F72-9GXX-98MJ
GHSA-WPPJ-C6MR-83JJ

Affected Products

Openclaw
Openshell