OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and senderIsOwner parameter manipulation. Attackers can exploit improper context validation to bypass sandbox restrictions and achieve unauthorized privilege escalation.
The vulnerability results from improper context validation (CWE-648 — improper use of privileges) during heartbeat context inheritance. An attacker manipulates the senderIsOwner parameter, allowing them to pass a false owner context within heartbeat communication. As a result, the sandbox mechanism incorrectly considers the attacker an authorized owner and grants them elevated privileges, bypassing imposed security restrictions.
An attacker can achieve unauthorized privilege escalation, potentially gaining full control over the application or system, and also affecting the confidentiality, integrity, and availability of both local and related system resources.
OpenClaw should be updated to version 2026.3.31 or later. A patch is available in the project repository (commit a30214a624946fc5c85c9558a27c1580172374fd). Details in the official security advisory from the vendor (GHSA-g5cg-8x5w-7jpm).
OpenClaw in versions before 2026.3.31
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XOpenclaw
APPOpenclaw< 2026.3.31
Related vulnerabilities
OpenClaw: ominięcie uwierzytelniania przez nieodświeżane tokeny bearer po rotacji SecretRef
OpenClaw: privilege escalation przez pominięcie zdarzeń async exec w heartbeat
OpenClaw: Authentication Bypass w trasie pomocniczej sandbox noVNC
OpenClaw: ekspozycja Chrome DevTools Protocol poza sandbox
OpenClaw — Auth Bypass w walidacji Feishu webhook umożliwia RCE