Junglewise Threat Intelligence

CVE-2026-32918: OpenClaw session_status sandbox escape

CVE-2026-32918 · Severity: low · CVSS 3.1 · Published 2026-03-13

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a multi-agent framework where sandboxed subagents can be spawned as child sessions to perform isolated work. The built-in session_status tool failed to validate sandbox boundaries, allowing a malicious child agent to read sensitive data from parent or sibling sessions and modify their configuration. An attacker could exfiltrate session state or manipulate model overrides across session boundaries.

Technical details

The vulnerability is an authorization bypass (CWE-863) in the session_status built-in tool. When a sandboxed subagent calls session_status with another session's sessionKey, the tool does not properly enforce sandbox visibility checks before reading or mutating session state. An authenticated attacker with low privileges who controls a child session can exploit this to inspect or modify parent/sibling session data without user interaction. The attack surface is limited to local/adjacent scenarios where the attacker can interact with the agent framework. Patches were released in versions 2026.3.11 and later, which now enforce session visibility checks before allowing state access.

Affected products

  • OpenClaw openclaw <= 2026.3.8

Timeline

  • 2026-03-13: disclosed
  • 2026-03-13: patched: Fixed in version 2026.3.11

References

Related threats