
🟠 CVE-2026-32918 - High OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or sibling session state. Attackers can s... https://www.thehackerwire.com/vulnerability/CVE-2026-32918/ https://t.co/ojdoUFVhKD
Post summary
OpenClaw before 2026.3.11 suffers a session sandbox escape bug that lets sandboxed subagents read other session states; no PoC, exploit, patch, or active usage reported yet.

