CVE 9.3 CRITICAL

OpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input_CVE-2026-42074

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashTool input schema, meaning the LLM (an untrusted principal per the project's own threat model) can set it to true in any tool_use response. Combined with the default allowUnsandboxedCommands: true setting, a prompt-injected model can escape the sandbox for any arbitrary command, achieving full host-level code execution. This issue has been patched in version 0.5.1.

AI Analysis

Sandbox bypass vulnerability allowing full host-level code execution via model-controlled input

Basic Information

ID CVE-2026-42074
Source GitHub_M
Published Jun 2, 2026 at 15:38

Affected Product

Vendor Gitlawb
Product openclaude
Version < 0.5.1
Affected Versions Gitlawb openclaude < 0.5.1

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Gitlawb
Product OpenClaude
Version < 0.5.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.