top of page
perceptive_background_267k.jpg

OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile function that allows sandbox escape. Atta…

Published:

20 april 2026 om 22:00:00

Alert date:

21 april 2026 om 17:05:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

OpenClaw versions before 2026.3.31 contain a critical time-of-check-time-of-use (TOCTOU) race condition vulnerability in the remote filesystem bridge readFile function. This security flaw allows attackers to escape sandbox restrictions by exploiting the timing gap between path validation and file read operations. The vulnerability enables unauthorized access to arbitrary files on the system, effectively bypassing the intended security boundaries of the sandbox environment. This represents a significant security risk as it could allow malicious actors to read sensitive files outside the intended scope of the application.

Technical details

Mitigation steps:

Affected products:

OpenClaw

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page