OpenClaw before 2026.3.2 contains a filesystem boundary bypass vulnerability in the image tool that fails to honor tools.fs.workspaceOnly restrictions. Attackers can traverse sandbox bridge mounts outside the workspace to read files that other filesystem tools would reject.
References
Configurations
History
13 Apr 2026, 20:31
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| First Time |
Openclaw openclaw
Openclaw |
|
| References | () https://github.com/openclaw/openclaw/commit/14baadda2c456f3cf749f1f97e8678746a34a7f4 - Patch | |
| References | () https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87 - Patch | |
| References | () https://github.com/openclaw/openclaw/commit/ccfeecb6887cd97937e33a71877ad512741e82b2 - Patch | |
| References | () https://github.com/openclaw/openclaw/commit/dd9d9c1c609dcb4579f9e57bd7b5c879d0146b53 - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-cfp9-w5v9-3q4h - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-filesystem-boundary-bypass-in-image-tool - Third Party Advisory |
10 Apr 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-10 17:17
Updated : 2026-04-13 20:31
NVD link : CVE-2026-35658
Mitre link : CVE-2026-35658
CVE.ORG link : CVE-2026-35658
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-668
Exposure of Resource to Wrong Sphere
