Time-of-check Time-of-use (TOCTOU) Race Condition in OpenClaw - #VU127182
Published: April 23, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a time-of-check time-of-use race condition in the OpenShell sandbox filesystem read bridge when handling filesystem read operations. A remote attacker can swap a symlink to cause bytes outside the intended mount root to be read and disclose sensitive information.