The break in assumption is that OpenShell is not a hard boundary. These flaws let code already inside the sandbox read and write outside the mount root, bypass allowlists, elevate privileges, and leave behind persistence that can look like normal agent activity.
Cyera disclosed four chained issues in OpenClaw/OpenShell: two TOCTOU races, an input-validation bypass in heredoc handling, and an access-control flaw that can impersonate an owner. The chain can expose credentials and internal files, tamper with configuration, and give control over gateway settings, cron scheduling, and execution management.
For teams using OpenShell to isolate untrusted jobs or automated shell execution, the risk is not just breakout. Once the sandbox is crossed, attacker actions can blend into expected automation and extend beyond the files and commands operators thought were contained.
CVSS 9.6 CRITICAL: openClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. EPSS 3% (85th percentile).
CVSS 7.7 HIGH: openClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. EPSS 0.2% (11th percentile).