Executive brief
OpenClaw is a popular Node.js library for sandbox file operations and workspace management. The vulnerability allows attackers to bypass time-of-check-time-of-use (TOCTOU) file integrity protections by exploiting check-then-act patterns in file operations (apply_patch, remove, mkdir), potentially enabling unauthorized file modification or deletion within sandboxed environments.
Technical details
The vulnerability is a classic time-of-check-time-of-use (TOCTOU) race condition (CWE-367) in sandbox file operations. The vulnerable code uses check-then-act patterns for apply_patch, remove, and mkdir operations instead of fd-based file descriptor operations that are atomic and race-resistant. An attacker with local access to the system and low privileges can exploit this race condition to change file target properties between the check and act phases, bypassing sandbox-workspace boundary protections. The attack requires precise timing and user interaction/system state manipulation. The fix (v2026.3.31) pins these operations to workspace-scoped mutations using more secure file descriptor-based approaches.
Affected products
- OpenClaw openclaw <=2026.3.28
Timeline
- 2026-04-03: disclosed: GHSA-rm5c-4rmf-vvhw published
- 2026-03-30: patched: Fix commit 32a4a47 merged
- 2026-03-31: other: Patched version 2026.3.31 released