CVE-2026-44112
OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge Writes
Description
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions and write files outside the local mount root.
No summary for this CVE yet.
CVSS Vector Breakdown
Exploitability
AV:NAttack VectorNetwork
AC:LAttack ComplexityLow
PR:LPrivileges RequiredLow
UI:NUser InteractionNone
Scope
S:CScopeChanged
Impact
C:NConfidentialityNone
I:HIntegrityHigh
A:HAvailabilityHigh
Weaknesses
Affected Products
OpenClaw
oss-projectaka clawdbot, crabbox
OpenClawLibrary
OSS Libraries / npmСообщество свободного программного обеспечения
oss-projectaka fsf
OpenClawOn-prem
Operating Systems and 1 more affected products View all →
Exploitability
Official Patch Available
Workaround Available
Attack Graph
Products CVE Techniques Tactics
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 technique Privilege Escalation
References
https://github.com/openclaw/openclaw/commit/7be82d4fd1193bcb7e44ee38838f00bf924ffa76
github.com
https://github.com/openclaw/openclaw/security/advisories/GHSA-wppj-c6mr-83jj
github.com
https://www.vulncheck.com/advisories/openclaw-symlink-swap-race-condition-in-openshell-fs-bridge-writes
vulncheck.com
and 1 more references View all →
News mentions
1Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-44112 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows
