CVE-2026-43529Patch(openclaw / openclaw)

LOWCVSS 2.0 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenClaw before 2026.4.10 contains a time-of-check-time-of-use vulnerability in the validateScriptFileForShellBleed function that allows local attackers to bypass workspace boundary checks. An attacker with workspace write access can race-condition swap the target file between validation and preflight read, causing the validator to inspect a different file identity than the one that passed the initial boundary check.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-05: 2Mentions · 2026-05-05: 1PoC Mentioned / Linked · 2026-03-05: 2Patch / Workaround · 2026-03-05: 2Technical Details · 2026-03-05: 2Technical Details · 2026-05-05: 103-0505-05
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-052
Patch2
2026-05-051
Disclosure1
Full discourse3 posts
  • Zero Day Engineering@zerodaytraining
    Patch

    Apple recently patched the missing piece in the userland part of the Dec'25 full-chain exploit. CVE-2026-20700: dyld memory corruption to PAC bypass This bug completes the chain of CVE-2026-43529 (jsc UAF RCE, PoC public) and CVE-2026-14174 (Angle OOB EoP, no working PoC yet). Patched in iOS 26.3

    Post summary

    Apple has released a patch (iOS 26.3) that closes the missing user‑land component of a series of linked exploits, notably CVE‑2026‑20700 which exploits dyld memory corruption to bypass PAC.

    22301827919.7K
    10.3K followersView on X
  • Hermes Tool@Hermes_tooll
    Patch

    Apple recently patched the missing piece in the userland part of the full-chain exploit. CVE-2026-20700: dyld memory corruption to PAC bypass This bug completes the chain of CVE-2026-43529 (jsc UAF RCE, PoC public) and CVE-2026-14174 (Angle OOB EoP, no working PoC yet) Patched

    Post summary

    Apple has released a patch addressing the memory corruption that bypasses PAC, completing the exploit chain for CVE‑2026‑20700, while a public PoC exists for CVE‑2026‑43529.

    08058225.3K
    1.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43529 OpenClaw before 2026.4.10 contains a time-of-check-time-of-use vulnerability in the validateScriptFileForShellBleed function that allows local attackers to bypass wor… https://www.cve.org/CVERecord?id=CVE-2026-43529

    Post summary

    The text announces CVE-2026-43529 as a time‑of‑check/time‑of‑use flaw in OpenClaw’s validateScriptFileForShellBleed function that can be leveraged by local attackers. No PoC, exploit, patch, or active exploitation details are provided.

    00010142
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more