OpenClaw versions prior to 2026.3.31 contain a critical sandbox bypass vulnerability that allows authenticated attackers to escalate privileges through manipulation of heartbeat context inheritance and the senderIsOwner parameter. The vulnerability exploits improper context validation mechanisms to circumvent sandbox restrictions and gain unauthorized elevated access. The vulnerability carries a CVSS severity rating of 9.9 CRITICAL with a network-based attack vector requiring only low complexity and low privilege access. The attack requires no user interaction and can compromise the entire system scope, resulting in complete compromise of confidentiality, integrity, and availability. The broader vulnerability landscape context indicates this poses a greater threat than approximately 99.89 percent of known CVEs. Currently, there is no evidence of active exploitation in the wild or public availability of functional exploit code. The vulnerability has not been assigned CVE/KEV status and remains inactive on threat intelligence watch lists. However, organizations running vulnerable versions should prioritize patching to OpenClaw 2026.3.31 or later due to the critical severity rating and relatively low exploitation barriers for motivated threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.31CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.31CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.