PT-2026-99233 · Openclaw · Openclaw
CVSS v4.0
8.8
High
| Vector | AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.7.1
Description
A time-of-check time-of-use (TOCTOU) race condition exists in OpenShell local mirror filesystem mutation operations. This occurs when the
remove, mkdir, and rename operations act on a filesystem target that changes after the sandbox path-safety check is completed. An attacker who successfully exploits this race condition can delete, create, or rename host paths outside the intended mirror root using the permissions of the OpenClaw process user, bypassing the need for granted host filesystem access outside the sandbox.Recommendations
Update to version 2026.7.1.
Exploit
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw