
🚨Critical - OpenClaude Sandbox Bypass via Model-Controlled dangerouslyDisableSandbox (CVE-2026-42074) The dangerouslyDisableSandbox parameter is exposed in the BashTool input schema, allowing the LLM (an untrusted principal) to set it to true. Combined with the default allowUnsandboxedCommands: true setting, this lets a prompt-injected model bypass the sandbox entirely and execute arbitrary commands on the host. This results in full host-level code execution. 👉Affected: openclaude < 0.5.1
Post summary
The tweet announces CVE‑2026‑42074, a sandbox bypass in OpenClaude where the dangerouslyDisableSandbox parameter can be set to true, enabling arbitrary host command execution on affected versions before 0.5.1.
