Executive brief
OpenClaw is a development tool that includes a sandboxing feature to restrict file operations within designated workspace areas. The experimental apply_patch feature bypasses these workspace-only restrictions in certain opt-in configurations, allowing operations on files outside the workspace, such as mounted system paths. This could permit unauthorized modification of files outside the intended workspace boundary.
Technical details
The vulnerability is a path traversal / access control bypass in the sandbox path resolution logic of the experimental apply_patch tool. In opt-in configurations where sandbox mode is enabled, the experimental apply_patch tool is enabled, and workspace-only restrictions are enforced, the apply_patch function failed to apply workspace-root assertions when resolving paths via sandbox.bridge.resolvePath(...). This allowed operations to target mounted paths outside the workspace root (e.g., /agent/...) that should have been restricted. An authenticated user with privileges to invoke apply_patch in such a configuration can modify files outside the workspace. The issue is fixed in version 2026.2.23, which applies the same workspace-only enforcement to sandbox-resolved paths as other filesystem tools.
Affected products
- OpenClaw OpenClaw <= 2026.2.22-2
Timeline
- 2026-03-03: disclosed
- 2026-02-24: patched: Fixed in version 2026.2.23