PT-2026-38246 · Openclaw+1 · Openclaw+1

Vladimir Tokarev

·

Published

2026-05-04

·

Updated

2026-05-28

·

CVE-2026-44113

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.22
Description A time-of-check/time-of-use (TOCTOU) race condition exists in the OpenShell filesystem bridge. This issue allows attackers to use symlink swaps during filesystem operations to bypass sandbox restrictions, enabling the reading of files outside the intended mount root and access to unauthorized file contents.
Recommendations Update to version 2026.4.22.

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2026-44113
GHSA-5H3G-6XHH-RG6P
GHSA-FRR5-J3MH-H9CH

Affected Products

Openclaw
Openshell