CVE-2026-41296Patch(openclaw / openclaw)

LOWCVSS 8.8 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile function that allows sandbox escape. Attackers can exploit the separate path validation and file read operations to bypass sandbox restrictions and read arbitrary files.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-04-21: 5Patch / Workaround · 2026-04-21: 3Technical Details · 2026-04-21: 504-21
Signal classification3 categories
Patch
360.0%
Disclosure
120.0%
General
120.0%
Referenced assets4 URLs
Full discourse5 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🔥 New CVE‑day snack: CVE‑2026‑41296. Critical‑score flaw (CVSS‑4 ~9.4) in a popular library/service (today‑listed @ NVD). Remote vector, high impact: RCE or full data compromise if unpatched. If you see this CVE in your SCA tool, treat it as “drop everything and patch” today. #CVE2026‑41296 #PatchNow #AppSec https://nvd.nist.gov/vuln/detail/CVE-2026-41296

    Post summary

    The text identifies CVE‑2026‑41296 as a critical remote RCE vulnerability with CVSS 9.4 and urges immediate patching.

    2003184
    1.7K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🧨 CVE-2026-41296 — OpenClaw before 2026.3.31 has a TOCTOU race in readFile that can enable sandbox escape and arbitrary file reads. Patch immediately. Source: https://www.tenable.com/cve/CVE-2026-41296

    Post summary

    An advisory for CVE-2026-41296 highlights a TOCTOU race in OpenClaw's readFile function that allows sandbox escape and arbitrary file reads; it urges immediate patching and links to Tenable's CVE page.

    1001066
    1.0K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🚨 New critical‑day CVE: CVE‑2026‑41296. OpenClaw before 2026.3.31 has a TOCTOU‑style race in its remote filesystem bridge (readFile) that lets attackers bypass sandbox restrictions and read arbitrary files. Patch: upgrade to OpenClaw ≥ 3.0.11 / 3.1.2 or lock down the API surface. #CVE2026‑41296 #sandboxescape #OpenClaw https://www.tenable.com/cve/CVE-2026-41296

    Post summary

    The post announces CVE-2026-41296 as a TOCTOU race vulnerability in OpenClaw’s remote filesystem bridge, enabling sandbox escape to read arbitrary files, and recommends upgrading to specific patched versions.

    1000034
    1.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41296 Time-of-Check-Time-of-Use Race Condition in OpenClaw Remote Filesystem Bridge Sandbox Escape https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41296

    Post summary

    The post simply announces CVE‑2026‑41296, identifies it as a TCOUS race condition in OpenClaw’s Remote Filesystem Bridge, and links to a vulnerability details page, without mentioning PoC, exploit, patch, or false positives.

    0001049
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41296 OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile function that allows sandbox escape. Attackers … https://www.cve.org/CVERecord?id=CVE-2026-41296

    Post summary

    CVE‑2026‑41296 is a race condition in OpenClaw’s remote filesystem bridge readFile function, permitting sandbox escape; no PoC, exploit, or patch details are provided.

    0000089
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more