CVE-2026-44112Disclosure(openclaw / openclaw)

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions and write files outside the local mount root.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 14 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 13 signals
  • Disclosure: 9 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 4 mentions (2026-05-15); latest day: 1
  • 14 total mentions across 10 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline14 mentions / 10d
01234Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-15: 4Mentions · 2026-05-17: 1Mentions · 2026-05-18: 2Mentions · 2026-05-29: 1Mentions · 2026-06-01: 1Mentions · 2026-06-12: 1Mentions · 2026-09-11: 1Mentions · 2026-09-26: 1Patch / Workaround · 2026-05-15: 2Patch / Workaround · 2026-05-17: 1Patch / Workaround · 2026-06-01: 1Patch / Workaround · 2026-09-11: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-15: 3Technical Details · 2026-05-17: 1Technical Details · 2026-05-18: 2Technical Details · 2026-05-29: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-12: 1Technical Details · 2026-09-11: 1Technical Details · 2026-09-26: 105-0605-0705-1505-1705-1805-2906-0106-1209-1109-26
Signal classification3 categories
Disclosure
964.3%
Patch
321.4%
General
214.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-061
General1
2026-05-071
Disclosure1
2026-05-154
Disclosure3Patch1
2026-05-171
Patch1
2026-05-182
Disclosure2
2026-05-291
General1
2026-06-011
Patch1
2026-06-121
Disclosure1
2026-09-111
Disclosure1
2026-09-261
Disclosure1
Full discourse14 posts
  • Ryx@PadhiyarRushi
    Disclosure

    OpenClaw “Claw Chain” is a clean example of AI-agent runtime becoming the attacker’s execution layer. Four bugs: • TOCTOU filesystem write escape (CVE-2026-44112, CVSS 9.6) • Env-var disclosure • MCP loopback owner-flag spoof (CVE-2026-44118) • Read-side TOCTOU Chain them and a sandbox foothold turns into credential theft + persistent host control. Patched in 2026.4.22, but the exposure window was large. https://www.cyera.com/research/four-new-openclaw-vulnerabilities-when-ai-agents-become-the-attackers-execution-layer #AISecurity #AgentSecurity #Cybersecurity #Infosec #Trending #AI #Claude #GPT

    Post summary

    The tweet announces four critical OpenClaw vulnerabilities and their exploitation chain, notes a patch released in 2026.4.22, but does not confirm active exploitation or provide PoC code.

    00031280
    954 followersView on X
  • motch | セキュリティ🛡️@motch_dev
    Disclosure

    CVE-2026-44112~44118、CVSS 9.6。OpenClaw AIエージェントに連鎖攻撃。 サンドボックス脱出から永続化まで4脆弱性を連結。 ↓詳細はリプライで #AIセキュリティ https://t.co/yWhRfiSagq

    Post summary

    The tweet announces a series of high‑scoring CVEs (2026‑44112 – 44118) and outlines a four‑step evasion chain, but it does not reference PoCs, exploitation tools, patches, or active attacks.

    1001061
    275 followersView on X
  • Ben Miller@bensen
    Disclosure

    the four “Claw Chain” vulnerabilities (CVE-2026-44112, 44113, 44115, 44118) were disclosed to maintainers by Cyera in April 2026 and patched in OpenClaw 2026.4.22 (April 23, 2026), see GHSA-5h3g-6xhh-rg6p, GHSA-wppj-c6mr-83jj, GHSA-r6xh-pqhr-v4xh, GHSA-x3h8-jrgh-p8jx on http://github.com/openclaw/openclaw/security/advisories

    Post summary

    Four Claw Chain vulnerabilities were disclosed, patched, and linked to GitHub advisories.

    00020133
    5.9K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    📍 CVE-2026-44112 مفهوم TOCTOU باختصار: النظام يفحص شيء ويتأكد إنه آمن، بعدين ينفذ . المهاجم يتدخل بين الفحص والتنفيذ ويبدّل المعطيات. النظام ينفذ بناءً على الفحص القديم بينما الواقع تغيّر. نظام OpenClaw يريد يكتب ملف داخل الـ Sandbox.

    Post summary

    The post describes the TOCTOU race condition underlying CVE‑2026‑44112, illustrating how an attacker can alter data between check and execution, but offers no PoC, exploit, patch, or evidence of active exploitation.

    10001359
    49.3K followersView on X
  • Kevin Kaminski@kkaminsk
    Patch

    The "Claw Chain" (CVE-2026-44112, CVSS 9.6 Critical) turns a supply chain foothold into full agent compromise through file ops and MCP protocol — no arbitrary code execution required. ~65K exposed instances on Shodan. Patch to v2026.4.22+ now.

    Post summary

    The post announces the critical Claw Chain vulnerability (CVE‑2026‑44112), notes its widespread exposure, and provides the patch version that resolves the issue.

    10000161
    1.4K followersView on X
  • Cyera@cyera_io
    Disclosure

    Cyera Research has just disclosed Claw Chain, a series of four chainable vulnerabilities in @openclaw, the open-source platform for autonomous AI agents. At the top of the chain is CVE-2026-44112, a CVSS 9.6 CRITICAL sandbox escape. https://t.co/6vL2oijeu2

    Post summary

    Cyera Research announced four chainable vulnerabilities in openclaw, highlighting CVE‑2026‑44112 as a critical sandbox escape (CVSS 9.6). The tweet contains no exploit code, patches, or evidence of active exploitation.

    10000171
    780 followersView on X
  • HumanAIFusion@humanaifusion
    Disclosure

    (2/6) CVE-2026-44112 | TOCTOU Write Escape | CVSS 9.6 CRITICAL OpenClaw: sandbox write redirected outside mount root via symlink race. Hermes-Agent: ALL terminal backends (local, Docker, SSH, Singularity, Modal, Daytona, Vercel) are exposed if paths resolve before write without atomic locking.

    Post summary

    The post reports CVE-2026-44112 as a critical TOCTOU write‑escape flaw affecting OpenClaw and Hermes‑Agent across various terminal backends, detailing how symlink races enable writes outside the mount root.

    10000109
    12 followersView on X
  • CiberInteligencia Chile@esecintelcl
    Patch

    🚨 OPENCLAW: 4 vulnerabilidades ("Claw Chain") permiten robo de datos, escalada de privilegios y persistencia 🔴 CVE-2026-44112, 44113, 44115, 44118 ✅ Actualizar a versión 2026.4.22 (para evitar explotación) #OpenClaw #CVE #Ciberseguridad #MCP https://t.co/oGdQhhKxId

    Post summary

    The post announces OpenClaw vulnerabilities enabling data theft, privilege escalation, and persistence, and recommends updating to version 2026.4.22 to block exploitation.

    00010122
    57 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 OPENCLAW — 20+ CVEs IN 2026 Sandbox escapes, auth bypasses, credential leaks. Peak: CVE-2026-44112 — CVSS 9.6 OpenShell sandbox escape. → https://threataft.com/articles/openclaw-mass-disclosure-20-cves-sandbox-escape #OpenClaw #CVE #AIAgents #PatchNow #CyberSecurity #ThreatIntel

    Post summary

    The tweet announces a mass disclosure of 20+ OpenClaw CVEs with technical highlights (sandbox escape, CVSS 9.6) and a link to an article, but provides no named patch, exploit tool, PoC, or active-exploitation evidence in the text itself.

    0000060
    45 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-44112: OpenClaw Sandbox Escape Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04jlNPp0

    Post summary

    The snippet only references the CVE in an article title, offering no concrete details or actionable information.

    0000049
    31 followersView on X
  • 0xPrashanthSec@0xprashanthSec
    Patch

    4 chained flaws in OpenClaw (CVE-2026-44112 to -44118) let attackers move from sandbox escape → credential theft → owner-level privesc → full persistence. CVSS 9.6 on the worst one. Patched in v2026.4.22. Update now. #Cybersecurity #CVE #AIAgents #BlueTeam #Infosec

    Post summary

    The text alerts that four chained CVEs in OpenClaw are extremely severe, provides the patch version v2026.4.22, and urges users to update.

    0000055
    44 followersView on X
  • Brandon()@brandonbango
    Disclosure

    OpenClaw Chain Vulnerabilities Expose 245,000 Public AI Agent Servers to Attack CVE-2026-44112 (CVSS 9.6 – Critical) CVE-2026-44115 (CVSS 8.8 – High) CVE-2026-44118 (CVSS 7.8 – High) CVE-2026-44113 (CVSS 7.7 – High)

    Post summary

    The article announces four critical/high severity OpenClaw Chain vulnerabilities affecting 245,000 AI agent servers, listing CVSS scores, but provides no evidence of exploits, patches, or PoC.

    0000076
    121 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44112 OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside … https://www.cve.org/CVERecord?id=CVE-2026-44112

    Post summary

    The post announces CVE‑2026‑44112, detailing a race condition in OpenClaw that enables attackers to redirect sandbox writes outside the intended scope, with no proof of active exploitation, PoC, or remediation highlighted.

    0000073
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-44112 Time-of-Check/Time-of-Use Race Condition in OpenClaw OpenShell Sandbox Filesystem Writes https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44112

    Post summary

    The text references CVE-2026-44112 as a time‑of‑check/time‑of‑use race condition in OpenClaw OpenShell Sandbox filesystems, but offers no proof of exploitation, mitigation steps, or detailed technical data.

    0000038
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more