---
id: CVE-2026-44113
title: >-
  OpenClaw < 2026.4.22 - Time-of-Check/Time-of-Use Race Condition in OpenShell
  FS Bridge
summary: >-
  OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition
  in the OpenShell filesystem bridge that allows attackers to read files outside
  the intended mount root. Attackers can exploit symlink swaps during filesystem
  o…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-367
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.4.22
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-05-07T13:04:19.393498Z'
published: '2026-05-06'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:17:40.205Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-44113'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-5h3g-6xhh-rg6p
    label: GitHub Security Advisory (GHSA-5h3g-6xhh-rg6p)
  - url: >-
      https://github.com/openclaw/openclaw/commit/95119017c847c737bd113f0bff728c4666d79c45
    label: Patch Commit
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-time-of-check-time-of-use-race-condition-in-openshell-fs-bridge
    label: >-
      VulnCheck Advisory: OpenClaw < 2026.4.22 - Time-of-Check/Time-of-Use Race
      Condition in OpenShell FS Bridge
tags:
  - cve.org
epss: 0.00336
epssPercentile: 0.24308
ingestedAt: '2026-09-24T15:45:56.731Z'
---

## Overview

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions and access unauthorized file contents.

## Affected

- `OpenClaw < 2026.4.22`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
