Vulnerabilities & Exploits
OpenShell Sandbox Break Lets Agents Hide Malicious Actions The break in assumption is that OpenShell is not a hard boundary. These flaws let code already inside the sandbox read and write outside the mount root, bypass allowlists, elevate privileges, and leave behind persistence that can look like normal agent activity.
Cyera disclosed four chained issues in OpenClaw/OpenShell: two TOCTOU races, an input-validation bypass in heredoc handling, and an access-control flaw that can impersonate an owner. The chain can expose credentials and internal files, tamper with configuration, and give control over gateway settings, cron scheduling, and execution management.
For teams using OpenShell to isolate untrusted jobs or automated shell execution, the risk is not just breakout. Once the sandbox is crossed, attacker actions can blend into expected automation and extend beyond the files and commands operators thought were contained.
3 sources · May 18
CVE-2026-44112 NVD KEV
CVSS 9.6 CRITICAL: openClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. EPSS 3% (85th percentile).
CVE-2026-44115 NVD KEV
CVSS 8.8 HIGH: openClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. EPSS 0.4% (28th percentile).
CVE-2026-44113 NVD KEV
CVSS 7.7 HIGH: openClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. EPSS 0.2% (11th percentile).
CVE-2026-44118 NVD KEV
CVSS 7.8 HIGH: openClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. EPSS 0.1% (2nd percentile).
Timeline Sources May 18 Dark Reading
'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments
The four flaws in the rapidly growing AI agent framework allow attackers to steal credentials, escalate privileges, and maintain persistence.
original May 18 SecurityWeek
‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery
Four vulnerabilities in OpenClaw can be chained together to steal credentials, escape the sandbox, and plant persistent backdoors.
original May 15 The Hacker News
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
Claw Chain flaws in OpenClaw 2026.4.22 enable data theft, privilege escalation, and persistence when chained.
original Part of the PlainSec briefing for 2026-05-18
Every edition of this story: OpenShell Sandbox Break Lets Agents Hide Malicious Actions
More from today
Vulnerabilities & Exploits
OpenShell Sandbox Break Lets Agents Hide Malicious Actions The break in assumption is that OpenShell is not a hard boundary. These flaws let code already inside the sandbox read and write outside the mount root, bypass allowlists, elevate privileges, and leave behind persistence that can look like normal agent activity.
Cyera disclosed four chained issues in OpenClaw/OpenShell: two TOCTOU races, an input-validation bypass in heredoc handling, and an access-control flaw that can impersonate an owner. The chain can expose credentials and internal files, tamper with configuration, and give control over gateway settings, cron scheduling, and execution management.
For teams using OpenShell to isolate untrusted jobs or automated shell execution, the risk is not just breakout. Once the sandbox is crossed, attacker actions can blend into expected automation and extend beyond the files and commands operators thought were contained.
3 sources · May 18
CVE-2026-44112 NVD KEV
CVSS 9.6 CRITICAL: openClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. EPSS 3% (85th percentile).
CVE-2026-44115 NVD KEV
CVSS 8.8 HIGH: openClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. EPSS 0.4% (28th percentile).
CVE-2026-44113 NVD KEV
CVSS 7.7 HIGH: openClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. EPSS 0.2% (11th percentile).
CVE-2026-44118 NVD KEV
CVSS 7.8 HIGH: openClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. EPSS 0.1% (2nd percentile).
Timeline Sources May 18 Dark Reading
'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments
The four flaws in the rapidly growing AI agent framework allow attackers to steal credentials, escalate privileges, and maintain persistence.
original May 18 SecurityWeek
‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery
Four vulnerabilities in OpenClaw can be chained together to steal credentials, escape the sandbox, and plant persistent backdoors.
original May 15 The Hacker News
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
Claw Chain flaws in OpenClaw 2026.4.22 enable data theft, privilege escalation, and persistence when chained.
original Part of the PlainSec briefing for 2026-05-18
Every edition of this story: OpenShell Sandbox Break Lets Agents Hide Malicious Actions
More from today