Race Condition Vulnerability in OpenClaw Remote Filesystem Bridge
CVE-2026-41296

8.8HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
20 April 2026

What is CVE-2026-41296?

A vulnerability in OpenClaw prior to version 2026.3.31 allows attackers to exploit a time-of-check-time-of-use race condition in the readFile function of the remote filesystem bridge. This issue arises from the separation of path validation and file read operations, which ultimately permits unauthorized access to arbitrary files outside the intended sandbox restrictions. Such exploitation leads to potential data exposure and increases the risk of further attacks.

Affected Version(s)

OpenClaw 0 < 2026.3.31

OpenClaw 2026.3.31

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AntAISecurityLab
.