PT-2026-28448 · Openclaw · Openclaw
CVSS v4.0
9.2
Crítica
| Vetor | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.11
Description
The software contains a session sandbox escape issue within the
session status tool. This allows sandboxed subagents to access session state belonging to parent or sibling sessions. An attacker can provide arbitrary sessionKey values to read or modify session data outside of their designated sandbox, potentially including persisted model overrides.Recommendations
Update to version 2026.3.11 or later.
Exploit
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openclaw