Executive brief
OpenClaw is a popular AI agent framework. A vulnerability in its session_status tool allows sandboxed subagents (restricted execution environments) to escape their sandbox and access or modify session data from parent or sibling sessions. An attacker could read sensitive session state or tamper with model configurations outside their intended scope.
Technical details
The session_status tool in OpenClaw fails to enforce session-visibility boundaries when processing sessionKey parameters. A sandboxed subagent can supply an arbitrary sessionKey to access or mutate session state belonging to parent or sibling sessions, including persisted model overrides. The vulnerability affects all versions up to 2026.3.8; it is a classic authorization bypass (CWE-863) requiring local/low-privilege access but allowing high impact to confidentiality and integrity within the OpenClaw execution environment. Patched in versions 2026.3.11 and later, which now enforce sandbox boundary checks before reading or modifying session state.
Affected products
- OpenClaw openclaw <=2026.3.8
Timeline
- 2026-03-13: disclosed
- 2026-03-29: patched: Fixed in version 2026.3.11 and later releases