8.8
/ 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Description
OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile function that allows sandbox escape. Attackers can exploit the separate path validation and file read operations to bypass sandbox restrictions and read arbitrary files.
AI Analysis
Sandbox escape via TOCTOU race in remote FS bridge readFile function
Basic Information
ID
CVE-2026-41296
Source
VulnCheck
Published
Apr 20, 2026 at 23:08
Affected Product
Vendor
OpenClaw
Product
OpenClaw
Affected Versions
OpenClaw OpenClaw 0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
OpenClaw
Product
OpenClaw
Version
< 2026.3.31