Race Condition Vulnerability in OpenClaw Remote Filesystem Bridge
CVE-2026-41296
8.8HIGH
What is CVE-2026-41296?
A vulnerability in OpenClaw prior to version 2026.3.31 allows attackers to exploit a time-of-check-time-of-use race condition in the readFile function of the remote filesystem bridge. This issue arises from the separation of path validation and file read operations, which ultimately permits unauthorized access to arbitrary files outside the intended sandbox restrictions. Such exploitation leads to potential data exposure and increases the risk of further attacks.
Affected Version(s)
OpenClaw 0 < 2026.3.31
OpenClaw 2026.3.31
