Junglewise Threat Intelligence

CVE-2026-35570: OpenClaude: Sandbox Bypass via Early-Exit Logic Flaw Allows Path Traversal

CVE-2026-35570 · Severity: high · CVSS 8.4 · Published 2026-04-21

Technologies: Gitlawb Openclaude. Vendors: npm.

Executive brief

OpenClaude is a code assistant framework that uses sandboxing to restrict bash command execution to a safe directory. A logic flaw in the permission check allows attackers with sandbox access to bypass directory restrictions using path traversal sequences (e.g., ../../../etc/passwd), enabling them to read sensitive files like .env files, SSH keys, and system files outside the intended sandbox boundary. This undermines the core filesystem isolation that the sandbox is designed to provide.

Technical details

The vulnerability exists in bashToolHasPermission() within src/tools/BashTool/bashPermissions.ts, where the sandbox auto-allow feature returns an allow decision immediately when no explicit deny rule is configured, bypassing the critical checkPathConstraints() validation step that filters path traversal attempts. The logic flaw occurs at approximately line 1445, where the function returns early without executing the path constraint filter at line 1644. An attacker operating in a sandboxed session with auto-allow enabled and no explicit deny rules can submit bash commands containing path traversal sequences to read or write arbitrary files subject to OS-level permissions. The vulnerability affects all versions prior to 0.5.1 and requires local access, low privileges, and no user interaction to exploit. Recommended fixes include continuing the permission pipeline to always evaluate path constraints or reordering the function to execute path validation before the sandbox auto-allow block.

Affected products

  • Gitlawb OpenClaude before 0.5.1

Timeline

  • 2026-04-21: disclosed
  • 2026-04-21: patched: Fixed in version 0.5.1

References

Related threats