MEDIUM
OpenClaw < 2026.2.19 - Race Condition in Sandbox Registry Write Operations
Published Mar 19, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.21%
Description
OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegistryEntry operations for sandbox containers and browsers. Attackers can exploit unsynchronized read-modify-write operations without locking to cause registry updates to lose data, resurrect removed entries, or corrupt sandbox state affecting list, prune, and recreate operations.
Affected products
-
- Version 0StatusaffectedConstraints<2026.2.19
- Version 2026.2.19StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.2.19
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.2.19 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://github.com/advisories/GHSA-gq83-8q7q-9hfx Advisory
- https://github.com/openclaw/openclaw/commit/cc29be8c9
- https://github.com/openclaw/openclaw/commit/cc29be8c9bcdfaecb90f0ab13124c8f5362a6741 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-gq83-8q7q-9hfx vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-32018
- https://www.vulncheck.com/advisories/openclaw-race-condition-in-sandbox-registry-write-operations third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-gq83-8q7q-9hfx | Advisory | |
| https://github.com/openclaw/openclaw/commit/cc29be8c9 | ||
| https://github.com/openclaw/openclaw/commit/cc29be8c9bcdfaecb90f0ab13124c8f5362a6741 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-gq83-8q7q-9hfx | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-32018 | ||
| https://www.vulncheck.com/advisories/openclaw-race-condition-in-sandbox-registry-write-operations | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 19, 2026
Updated Jun 23, 2026
Reserved Mar 10, 2026
Link CVE-2026-32018
CISA Vulnrichment
GHSA-GQ83-8Q7Q-9HFX Updated Mar 20, 2026