Junglewise Threat Intelligence

CVE-2026-43529: OpenClaw TOCTOU race in exec script preflight

CVE-2026-43529 · Severity: medium · CVSS 4 · Published 2026-04-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a development tool that validates scripts before execution as a sandbox boundary check. A timing vulnerability allows a local attacker with write access to the workspace to swap a script file between the validation and execution steps, potentially bypassing security checks and exposing limited metadata from unauthorized files (such as matched tokens or line numbers).

Technical details

The vulnerability is a time-of-check-time-of-use (TOCTOU) race condition in the validateScriptFileForShellBleed function, which performs separate path validation (assertSandboxPath), file stat, and file read operations on a mutable pathname. An attacker with write access to the workspace can replace the target file (via symlink swap) between the validation and read steps, causing the preflight analysis to inspect a different file than the one that passed the boundary check. The attack requires precise timing to race between validation and read, and is limited to disclosing derived content (token matches, line numbers, first non-empty JS line) rather than full file contents. The fix (v2026.4.10) replaces the three-step check-then-read pattern with an atomic readFileWithinRoot call that pins the file descriptor after open, verifies boundary around the opened file identity, and uses O_NOFOLLOW to prevent symlink following.

Affected products

  • OpenClaw OpenClaw < 2026.4.10

Timeline

  • 2026-04-16: disclosed: GHSA-gj9q-8w99-mp8j published
  • 2026-04-10: patched: Fix shipped in v2026.4.10 (fix commit b024fae9e5df43e9b69b2daebb72be3469d52e91)

References

Related threats