---
id: CVE-2026-44112
title: >-
  OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge
  Writes
summary: >-
  OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition
  in OpenShell sandbox filesystem writes that allows attackers to redirect
  writes outside the intended mount root. Attackers can exploit symlink swaps
  during fil…
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-367
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.4.22
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-05-07T17:25:18.853727Z'
published: '2026-05-06'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:17:38.954Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-44112'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-wppj-c6mr-83jj
    label: GitHub Security Advisory (GHSA-wppj-c6mr-83jj)
  - url: >-
      https://github.com/openclaw/openclaw/commit/7be82d4fd1193bcb7e44ee38838f00bf924ffa76
    label: Patch Commit
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-symlink-swap-race-condition-in-openshell-fs-bridge-writes
    label: >-
      VulnCheck Advisory: OpenClaw < 2026.4.22 - Symlink Swap Race Condition in
      OpenShell FS Bridge Writes
tags:
  - cve.org
epss: 0.00389
epssPercentile: 0.30179
ingestedAt: '2026-09-24T15:45:56.730Z'
---

## Overview

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions and write files outside the local mount root.

## Affected

- `OpenClaw < 2026.4.22`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
