Description
OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to enforce tools.fs.workspaceOnly restrictions on mounted sandbox paths, allowing attackers to read out-of-workspace files. Attackers can load restricted mounted images and exfiltrate them through vision model provider requests to bypass sandbox confidentiality controls.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
Any version before 2026.2.23
2026.2.23 (semver)
Credits
tdjackey
References
github.com/...enclaw/security/advisories/GHSA-q6qf-4p5j-r25g (GitHub Security Advisory (GHSA-q6qf-4p5j-r25g))
github.com/...ommit/dd9d9c1c609dcb4579f9e57bd7b5c879d0146b53 (Patch Commit)
www.vulncheck.com/...ass-via-image-tool-workspaceonly-bypass (VulnCheck Advisory: OpenClaw < 2026.2.23 - Sandbox Boundary Bypass via Image Tool workspaceOnly Bypass)