CVE-2026-42074Disclosure(gitlawb / openclaude)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashTool input schema, meaning the LLM (an untrusted principal per the project's own threat model) can set it to true in any tool_use response. Combined with the default allowUnsandboxedCommands: true setting, a prompt-injected model can escape the sandbox for any arbitrary command, achieving full host-level code execution. This issue has been patched in version 0.5.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaude

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
openclaude

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-12: 1Technical Details · 2026-05-12: 105-12
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - OpenClaude Sandbox Bypass via Model-Controlled dangerouslyDisableSandbox (CVE-2026-42074) The dangerouslyDisableSandbox parameter is exposed in the BashTool input schema, allowing the LLM (an untrusted principal) to set it to true. Combined with the default allowUnsandboxedCommands: true setting, this lets a prompt-injected model bypass the sandbox entirely and execute arbitrary commands on the host. This results in full host-level code execution. 👉Affected: openclaude < 0.5.1

    Post summary

    The tweet announces CVE‑2026‑42074, a sandbox bypass in OpenClaude where the dangerouslyDisableSandbox parameter can be set to true, enabling arbitrary host command execution on affected versions before 0.5.1.

    0003096
    255 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlawbopenclaude---

Explore more