Vulnerabilità ed exploit

OpenShell Sandbox Break Consente agli Agent di Nascondere Azioni Malevole

La rottura dell’assunzione è che OpenShell non è un confine rigido. Questi flaw consentono al codice già all’interno della sandbox di leggere e scrivere al di fuori della mount root, bypassare le allowlist, elevare i privilegi e lasciare dietro di sé persistence che può sembrare normale attività dell’agent.

3 fonti · 19 mag

CVE-2026-44115

NVD KEV

CVSS 8.8 HIGH: openClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. EPSS 0.6% (47º percentile).

CVE-2026-44112

NVD KEV

CVSS 9.6 CRITICAL: openClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. EPSS 0.4% (30º percentile).

CVE-2026-44113

NVD KEV

CVSS 7.7 HIGH: openClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. EPSS 0.3% (24º percentile).

CVE-2026-44118

NVD KEV

CVSS 7.8 HIGH: openClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. EPSS 0.2% (4º percentile).

Cronologia

Fonti

Part of the PlainSec briefing for 2026-05-15

Every edition of this story: OpenShell Sandbox Break Consente agli Agent di Nascondere Azioni Malevole

Altro da oggi