Junglewise Threat Intelligence

CVE-2026-33573: OpenClaw Gateway agent workspace boundary bypass

CVE-2026-33573 · Severity: low · CVSS 3.1 · Published 2026-03-13

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI-powered automation platform that executes tasks across various operating systems and platforms. The gateway component, which orchestrates agent operations, contained a security flaw that allowed authenticated operators to override configured workspace boundaries and execute commands outside their intended scope. This could enable unauthorized file access, modification, or arbitrary command execution on systems where the agent runs.

Technical details

The vulnerability exists in OpenClaw's public gateway agent RPC interface, which accepted attacker-controlled `spawnedBy` and `workspaceDir` parameters from authenticated operators possessing the `operator.write` privilege. The gateway failed to enforce the configured workspace boundary when these parameters were supplied, allowing a caller to re-root the agent execution context outside its intended scope. An authenticated operator without owner privileges could exploit this to access files and run file/exec tools from any directory accessible to the agent process. The root cause was insufficient parameter validation and boundary enforcement. The fix, released in version 2026.3.11, adds enforcement of the configured workspace boundary regardless of caller-supplied overrides. The vulnerability requires network access, authentication with operator.write role, and no user interaction, resulting in high impact across confidentiality, integrity, and availability.

Affected products

  • OpenClaw openclaw <= 2026.3.8

Timeline

  • 2026-03-13: disclosed
  • 2026-03-11: patched: Fix released in version 2026.3.11 and included in later releases

References

Related threats