CVE-2026-32977

MEDIUM6.3EPSS 0.01%

OpenClaw: Sandbox `writeFile` commit could race outside the validated path

發布日:2026/3/13修改日:2026/4/6

描述

## Summary In affected versions of `openclaw`, the sandbox fs-bridge `writeFile` commit step used an unanchored container path during the final move into place. An attacker racing parent-path changes inside the sandbox could redirect the committed file outside the validated sandbox path. ## Impact This is a sandbox boundary bypass. In-sandbox code could win a time-of-check-time-of-use race and cause host-approved `writeFile` operations to land outside the validated writable path within the container mount namespace. ## Affected Packages and Versions - Package: `openclaw` (npm) - Affected versions: `< 2026.3.11` - Fixed in: `2026.3.11` ## Technical Details The hardening work for anchored remove, rename, and mkdir operations did not fully cover the `writeFile` commit path. The final `mv` still used the raw target path, leaving a race window between safety revalidation and the in-container commit step. ## Fix OpenClaw now anchors the `writeFile` commit path to the canonical parent directory before the final move. The fix shipped in `[email protected]`. ## Workarounds Upgrade to `2026.3.11` or later.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.3CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H

參考連結(5)