Executive brief
OpenClaw, an AI assistant platform, contains a security flaw that allows sandboxed AI agents to bypass their restricted environments. By using specific parameters in tool calls, a malicious or compromised agent can read sensitive files from other agents' workspaces, including API keys, session logs, and credentials. This effectively breaks the isolation between different users or tasks on the same system.
Technical details
A path traversal vulnerability (CWE-22) exists in OpenClaw's agent sandbox enforcement due to incomplete parameter validation and context stripping. The 'normalizeSandboxMediaParams' function in 'message-action-params.ts' uses a hardcoded allowlist of keys (media, path, filePath) to validate paths, but fails to include 'mediaUrl' and 'fileUrl'. Additionally, 'handlePluginAction' in 'message-action-runner.ts' omits 'mediaLocalRoots' when dispatching actions, causing plugins to fall back to default roots that permit access to the entire '~/.openclaw/' directory. An attacker can exploit this by crafting a tool call with an unnormalized key pointing to a file outside their sandbox, leading to a full sandbox escape and unauthorized file disclosure. The issue is fixed in version 2026.3.24.
Affected products
- OpenClaw openclaw < 2026.3.24
Timeline
- 2026-03-27: disclosed
- 2026-03-30: advisory: GitHub Advisory published
- 2026-03-24: patched