OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows attackers to bypass fd-based defenses. Attackers can exploit check-then-act patterns in apply_patch, remove, and mkdir operations to manipulate files between validation and execution.
References
Configurations
History
No history.
Information
Published : 2026-04-23 22:16
Updated : 2026-06-17 10:46
NVD link : CVE-2026-41338
Mitre link : CVE-2026-41338
CVE.ORG link : CVE-2026-41338
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
