Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

TOCTOU Sandbox Escape in OpenClaw OpenShell Filesystem Writes

IdentifiersCVE-2026-44112CWE-367· Time-of-check Time-of-use (TOCTOU)…

CVE-2026-44112 is a critical time-of-check/time-of-use (TOCTOU) race condition in the OpenShell managed sandbox backend of OpenClaw. In affected versions prior to 2026.4.22 / before April 23, 2026, filesystem write operations within the sandbox validate a target path against the intended mount root, but an attacker can win a race by swapping the checked path with a symlink or other redirect before the write occurs. This allows write operations to be redirected outside the sandbox boundary and outside the intended local mount root, defeating the filesystem isolation enforced by OpenShell.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an attacker to escape the intended write restrictions of the OpenShell sandbox and modify files outside the permitted mount root. Reported impacts include configuration tampering, placement of persistent backdoors on the host, and establishment of persistent control when used as part of the broader Claw Chain attack path. Because the attack abuses the agent’s own execution context and privileges, malicious activity may blend with normal agent behavior and increase detection difficulty.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by restricting OpenClaw instances behind authentication and firewall controls, eliminating unnecessary public internet access, and limiting the agent’s filesystem permissions and host-level privileges as much as operationally possible. Closely monitor for unexpected file writes, configuration changes, and symlink manipulation in sandbox-accessible paths. Treat any untrusted plugin, prompt input, or external content as a potential initial foothold for chained exploitation.

Remediation

Patch, then assume compromise.

Upgrade OpenClaw to version 2026.4.22 or later; all affected versions released before April 23, 2026 should be considered vulnerable. Apply the vendor's April 23, 2026 fixes associated with the Claw Chain disclosures. After patching, review host and agent configuration for unauthorized modifications, remove any planted backdoors or persistence mechanisms, and rotate potentially exposed secrets if compromise is suspected.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
OpenclawOpenclawapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity4

Community discussion across Reddit, Mastodon, and other social sources.