Junglewise Threat Intelligence

CVE-2026-44112: OpenClaw TOCTOU race condition in OpenShell sandbox filesystem writes

CVE-2026-44112 · Severity: critical · CVSS 9.6 · Published 2026-05-06

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a software framework that includes a sandboxed environment for executing code. A security flaw in its filesystem bridge allows an attacker to bypass sandbox restrictions and write files to unauthorized locations on the host system. This could lead to the corruption of sensitive system files or the placement of malicious files outside the intended secure area.

Technical details

A time-of-check/time-of-use (TOCTOU) race condition exists in the OpenShell filesystem bridge of OpenClaw. By performing a symlink swap during filesystem operations, an attacker with low privileges can redirect write operations to locations outside the designated sandbox mount root. The vulnerability stems from the bridge failing to properly pin host writes to the sandbox root during the window between path validation and the actual write operation. This issue is addressed in version 2026.4.22 by validating canonical targets, rejecting unsafe symlink parents/leaves, and implementing root-scoped write helpers.

Affected products

  • OpenClaw OpenClaw < 2026.4.22

Timeline

  • 2026-04-23: advisory: Vendor advisory GHSA-wppj-c6mr-83jj published
  • 2026-05-06: disclosed: CVE-2026-44112 published
  • 2026-04-22: patched: Version 2026.4.22 released with fix

References

Related threats