Executive brief
Crabbox, a tool for managing sandboxed development environments, contains a security flaw in how it handles workspace paths for its Islo provider. An attacker can include a malicious configuration file in a repository that, when opened by a user, causes Crabbox to delete or overwrite critical system files within the sandbox environment. This could lead to data loss or the corruption of the isolated environment used for development tasks.
Technical details
A path traversal vulnerability exists in Crabbox's Islo provider due to insufficient validation of the 'islo.workdir' parameter in configuration files (.crabbox.yaml or crabbox.yaml). The 'isloWorkspacePath()' function fails to properly sanitize absolute paths or relative paths containing traversal sequences (e.g., '../etc'), allowing them to resolve outside the intended '/workspace' directory. When 'sync.delete' is enabled, the workspace preparation logic executes 'rm -rf' and 'mkdir -p' on these resolved paths. An attacker can exploit this by tricking a user into running Crabbox against a malicious repository, leading to arbitrary file deletion or overwrites within the provider-side filesystem. This issue was addressed in version 0.9.0 by enforcing that all workdir paths are relative and contained strictly under the '/workspace' root.
Affected products
- openclaw Crabbox < 0.9.0
Timeline
- 2026-05-09: patched: Fix merged in pull request #65
- 2026-05-11: disclosed: CVE-2026-45224 published
- 2026-05-11: advisory