


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile function that allows sandbox escape. Atta…
Published:
20 april 2026 om 22:00:00
Alert date:
21 april 2026 om 17:05:49
Source:
nvd.nist.gov
Web Technologies
OpenClaw versions before 2026.3.31 contain a critical time-of-check-time-of-use (TOCTOU) race condition vulnerability in the remote filesystem bridge readFile function. This security flaw allows attackers to escape sandbox restrictions by exploiting the timing gap between path validation and file read operations. The vulnerability enables unauthorized access to arbitrary files on the system, effectively bypassing the intended security boundaries of the sandbox environment. This represents a significant security risk as it could allow malicious actors to read sensitive files outside the intended scope of the application.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41296
https://github.com/openclaw/openclaw/commit/121870a08583033ed6a0ed73d9ffea32991252bb
https://github.com/openclaw/openclaw/security/advisories/GHSA-9p3r-hh9g-5cmg
https://www.vulncheck.com/advisories/openclaw-sandbox-escape-via-toctou-race-in-remote-fs-bridge-readfile
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
