CVE-2026-32988: OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File Creation
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path before the final guarded replace step executes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32988?
CVE-2026-32988 is classified as a medium severity vulnerability due to its potential for sandbox boundary bypass.
How can I fix CVE-2026-32988?
To fix CVE-2026-32988, update OpenClaw to version 2026.3.11 or later, which addresses the sandbox boundary bypass issue.
What systems are affected by CVE-2026-32988?
The affected version of OpenClaw is any version prior to 2026.3.11.
What does CVE-2026-32988 exploit?
CVE-2026-32988 exploits unvalidated temporary file creation to bypass sandbox boundaries in OpenClaw.
What is the impact of CVE-2026-32988?
The impact of CVE-2026-32988 allows attackers to create files outside of a verified parent directory, potentially leading to privilege escalation.