CRITICAL
OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
Published Apr 20, 2026
9.0
CRITICALCVSS 4.0
EPSS 0.52%
Description
OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and senderIsOwner parameter manipulation. Attackers can exploit improper context validation to bypass sandbox restrictions and achieve unauthorized privilege escalation.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.31
- Version 2026.3.31StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.31
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.31 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24017 Advisory
- https://github.com/advisories/GHSA-g5cg-8x5w-7jpm Advisory
- https://github.com/openclaw/openclaw/commit/a30214a624946fc5c85c9558a27c1580172374fd patch
- https://github.com/openclaw/openclaw/releases/tag/v2026.3.31
- https://github.com/openclaw/openclaw/security/advisories/GHSA-g5cg-8x5w-7jpm vendor-advisoryVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-sandbox-bypass-via-heartbeat-context-inheritance-and-senderisowner-escalation third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24017 | Advisory | |
| https://github.com/advisories/GHSA-g5cg-8x5w-7jpm | Advisory | |
| https://github.com/openclaw/openclaw/commit/a30214a624946fc5c85c9558a27c1580172374fd | patch | |
| https://github.com/openclaw/openclaw/releases/tag/v2026.3.31 | ||
| https://github.com/openclaw/openclaw/security/advisories/GHSA-g5cg-8x5w-7jpm | vendor-advisoryVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-sandbox-bypass-via-heartbeat-context-inheritance-and-senderisowner-escalation | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 20, 2026
Updated Apr 21, 2026
Reserved Apr 20, 2026
Link CVE-2026-41329
CISA Vulnrichment
Updated Apr 21, 2026
ENISA EUVD
EUVD-2026-24017 GHSA-G5CG-8X5W-7JPM Assigner VulnCheck
Published Apr 20, 2026
Updated Apr 21, 2026
Exploited since n/a
Link EUVD-2026-24017