Description
OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to create child processes under unsandboxed agents. An attacker with a sandboxed session can exploit this to spawn child runtimes with sandbox.mode set to off, bypassing runtime confinement restrictions.
Problem types
CWE-732: Incorrect Permission Assignment for Critical Resource
Product status
Any version before 2026.3.1
2026.3.1 (semver)
Credits
tdjackey
References
github.com/...enclaw/security/advisories/GHSA-p7gr-f84w-hqg5 (GitHub Security Advisory (GHSA-p7gr-f84w-hqg5))
www.vulncheck.com/...x-escape-via-cross-agent-sessions-spawn (VulnCheck Advisory: OpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawn)