Sandbox Escape Vulnerability in OpenClaw by OpenClaw
CVE-2026-41397

7.6HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-41397?

OpenClaw versions prior to 2026.3.31 are susceptible to a sandbox escape vulnerability that permits unauthorized directory traversal. Attackers can exploit this flaw by crafting malicious symlinks during file synchronization operations, enabling them to bypass the established sandbox restrictions and gain access to sensitive files outside of the designated boundaries. This vulnerability poses a significant risk as it compromises the integrity of file management processes, allowing potential data leakage or unauthorized access.

Affected Version(s)

OpenClaw 0 < 2026.3.31

OpenClaw 2026.3.31

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AntAISecurityLab
.