CVE-2026-41296 is a time-of-check-time-of-use race condition vulnerability in OpenClaw's remote filesystem bridge readFile function that affects versions prior to 2026.3.31. The flaw enables sandbox escape by exploiting a gap between path validation and file read operations, allowing attackers to circumvent sandbox restrictions and access arbitrary files on the system. The vulnerability carries a CVSS score of 8.2 (HIGH) with a network attack vector, high complexity, and low privilege requirements. While user interaction is not required, the attack has significant impact potential, compromising confidentiality and integrity across system boundaries. The EPSS score of 0.00026 indicates relatively low probability of exploitation in the wild compared to other disclosed vulnerabilities. There is no evidence of active exploitation at this time, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog. Community attention appears limited, reflected by the moderate FAUCET Risk Score of 49.0 out of 100. Organizations using OpenClaw should prioritize patching to version 2026.3.31 or later to mitigate this sandbox escape risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.31CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.31CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.