Executive brief
OpenClaw is a distributed runtime system that uses sandboxing to confine untrusted code execution. In multi-agent environments, a sandboxed session could bypass its confinement by spawning child processes under an agent configured with sandboxing disabled, effectively escaping the security boundary. This allows an attacker to gain unrestricted code execution access that the sandbox was designed to prevent.
Technical details
OpenClaw's sessions_spawn function in cross-agent setups failed to enforce sandbox inheritance constraints. A sandboxed session could invoke cross-agent spawning to create child processes under an agent with sandbox.mode="off", downgrading runtime confinement from sandboxed to unsandboxed execution. The vulnerability affects mixed-agent deployments where cross-agent spawning is permitted, requiring only network access with no authentication required. An attacker can escape sandbox restrictions and gain unrestricted code execution. The fix enforces spawn-time sandbox inheritance validation: spawn operations are now rejected if the requester is sandboxed but the target child runtime would be unsandboxed. Patched in version 2026.3.1 and later.
Affected products
- OpenClaw OpenClaw <=2026.2.26
Timeline
- 2026-03-02: disclosed
- 2026-03-01: patched: Version 2026.3.1 available