Executive brief
OpenClaw is a node-based execution framework for running distributed tasks and agents. A vulnerability allows sandboxed agents to bypass security isolation by overriding the host parameter, enabling them to execute code on remote nodes instead of within their intended sandbox environment. This breaks the sandbox boundary and allows an attacker with agent-level access to escape confinement.
Technical details
A privilege escalation and sandbox escape vulnerability exists in OpenClaw's exec routing logic (CWE-863: Improper Authorization). A sandboxed agent can override the host parameter to "node" and request remote execution instead of the intended sandbox path, bypassing the routing boundary enforcement. The vulnerability requires authentication (agent credentials) and network access to the OpenClaw cluster. An attacker with a compromised or malicious agent can execute arbitrary code on remote nodes outside the sandbox. The fix (PR #63880, commit dffad08) blocks sandboxed exec escape to remote node targets and enforces routing alignment with the active sandbox policy. Patched versions are 2026.4.10 and later.
Affected products
- OpenClaw OpenClaw >= 2026.4.5 < 2026.4.10
Timeline
- 2026-04-17: disclosed
- 2026-04-17: patched: Fix in PR #63880, patched in v2026.4.10
- 2026-05-05: advisory: NVD published CVE-2026-42434