The break in assumption is that OpenShell is not a hard boundary. These flaws let code already inside the sandbox read and write outside the mount root, bypass allowlists, elevate privileges, and leave behind persistence that can look like normal agent activity.
Cyera disclosed four chained issues in OpenClaw/OpenShell: two TOCTOU races, an input-validation bypass in heredoc handling, and an access-control flaw that can impersonate an owner. The chain can expose credentials and internal files, tamper with configuration, and give control over gateway settings, cron scheduling, and execution management.
For teams using OpenShell to isolate untrusted jobs or automated shell execution, the risk is not just breakout. Once the sandbox is crossed, attacker actions can blend into expected automation and extend beyond the files and commands operators thought were contained.