Опубликовано: 31 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.8
CVSS3: 6.3
Описание
Duplicate Advisory: OpenClaw: Sandbox writeFile commit could race outside the validated path
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-xvx8-77m6-gwg6. This link is maintained to preserve external references.
Original Description
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths inside the sandbox to redirect committed files outside the validated writable path within the container mount namespace.
Пакеты
Наименование
openclaw
npm
Затронутые версииВерсия исправления
< 2026.3.11
2026.3.11
5.8 Medium
CVSS4
6.3 Medium
CVSS3
Дефекты
CWE-367
5.8 Medium
CVSS4
6.3 Medium
CVSS3
Дефекты
CWE-367