Vulnerabilities & Exploits

OpenShell Sandbox Break Lets Agents Hide Malicious Actions

The break in assumption is that OpenShell is not a hard boundary. These flaws let code already inside the sandbox read and write outside the mount root, bypass allowlists, elevate privileges, and leave behind persistence that can look like normal agent activity.

Cyera disclosed four chained issues in OpenClaw/OpenShell: two TOCTOU races, an input-validation bypass in heredoc handling, and an access-control flaw that can impersonate an owner. The chain can expose credentials and internal files, tamper with configuration, and give control over gateway settings, cron scheduling, and execution management.

For teams using OpenShell to isolate untrusted jobs or automated shell execution, the risk is not just breakout. Once the sandbox is crossed, attacker actions can blend into expected automation and extend beyond the files and commands operators thought were contained.

3 sources · May 18

CVE-2026-44112

NVD KEV

CVSS 9.6 CRITICAL: openClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. EPSS 3% (85th percentile).

CVE-2026-44115

NVD KEV

CVSS 8.8 HIGH: openClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. EPSS 0.4% (28th percentile).

CVE-2026-44113

NVD KEV

CVSS 7.7 HIGH: openClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. EPSS 0.2% (11th percentile).

CVE-2026-44118

NVD KEV

CVSS 7.8 HIGH: openClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. EPSS 0.1% (2nd percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-19

Every edition of this story: OpenShell Sandbox Break Lets Agents Hide Malicious Actions

More from today