CVE-2026-44115
CVSS 8.8 HIGH: openClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. EPSS 0.6% (47º percentile).
Vulnerabilità · 134 giorni fa
La rottura dell’assunzione è che OpenShell non è un confine rigido. Questi flaw consentono al codice già all’interno della sandbox di leggere e scrivere al di fuori della mount root, bypassare le allowlist, elevare i privilegi e lasciare dietro di sé persistence che può sembrare normale attività dell’agent.
CVSS 8.8 HIGH: openClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. EPSS 0.6% (47º percentile).
CVSS 9.6 CRITICAL: openClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. EPSS 0.4% (30º percentile).
CVSS 7.7 HIGH: openClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. EPSS 0.3% (24º percentile).
CVSS 7.8 HIGH: openClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. EPSS 0.2% (4º percentile).
3 fonti che coprono questa storia
'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments
The four flaws in the rapidly growing AI agent framework allow attackers to steal credentials, escalate privileges, and maintain persistence.
‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery
Four vulnerabilities in OpenClaw can be chained together to steal credentials, escape the sandbox, and plant persistent backdoors.
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
Claw Chain flaws in OpenClaw 2026.4.22 enable data theft, privilege escalation, and persistence when chained.
Part of the PlainSec briefing for 2026-05-19