OpenClaw Sandbox Boundary Bypass Vulnerability in WriteFile Commit Step
Vulnerability
A sandbox boundary bypass vulnerability has been identified in OpenClaw versions prior to 2026.3.11. The issue arises in the fs-bridge writeFile commit step, where an unanchored container path is used during the final move operation. This flaw allows an attacker to exploit a time-of-check-time-of-use race condition by altering parent paths within the sandbox, redirecting committed files outside the validated writable path within the container mount namespace.
Impact
Exploitation of this vulnerability can lead to a sandbox boundary bypass, allowing in-sandbox code to manipulate host-approved writeFile operations and place files outside the intended writable path within the container's mount namespace.
Remediation
Users are advised to upgrade to OpenClaw version 2026.3.11 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
