PT-2026-23506 · Openclaw · Openclaw

·

CVE-2026-43529

·

Published

2026-03-05

·

Updated

2026-05-05

CVSS v3.1

2.5

Low

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.10
Description A time-of-check-time-of-use (TOCTOU) issue exists in the validateScriptFileForShellBleed() function. A TOCTOU issue is a software bug where a system checks a condition (such as a security credential) and then uses the result of that check to perform an action, but the condition changes between the check and the use. This allows local attackers with workspace write access to bypass workspace boundary checks by using a race condition to swap the target file between the validation and preflight read phases. This causes the validator to inspect a different file identity than the one that initially passed the boundary check.
Recommendations Update to version 2026.4.10 or newer.

Exploit

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43529
GHSA-GJ9Q-8W99-MP8J

Affected Products

Openclaw