GHSA-474h-prjg-mmw3
### Summary Sandboxed `sessions_spawn(runtime="acp")` could bypass sandbox inheritance and initialize host-side ACP runtime. The fix now fail-closes ACP spawn from sandboxed requester sessions and rejects `sandbox="require"` for `runtime="acp"`. ### Affected Packages / Versions - Package: `openclaw` (npm) - Latest published npm version at triage time: `2026.3.1` (March 2, 2026) - Vulnerable range: `<=2026.3.1` - Patched release: `2026.3.2` (released) ### Technical Details - Root cause: `runtime="subagent"` enforced sandbox inheritance, while `runtime="acp"` did not enforce equivalent sandbox/runtime checks. - Security impact: sandbox-boundary bypass into host-side ACP initialization. - Fixed behavior: - deny ACP spawn when requester runtime is sandboxed - deny `sessions_spawn` with `runtime="acp", sandbox="require"` - align sandboxed prompt guidance to avoid advertising blocked ACP paths ### Fix Commit(s) - `ac11f0af731d41743ba02d8595f4d0fe747336e3` - `c703aa0fe92df9fb71cf254fc46991e05fba2114`
Properties
- ghsa_id
- GHSA-474h-prjg-mmw3
- severity
- high
- summary
- OpenClaw: Sandboxed sessions_spawn(runtime="acp") bypassed sandbox inheritance and allowed host ACP initialization
- cvss_score
- 8.1
- cve_id
- GHSA-474h-prjg-mmw3
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
- is_ghsa_only
- true
- ghsa_published
- 2026-03-03T21:31:57Z
- source_url
- https://github.com/advisories/GHSA-474h-prjg-mmw3
- ghsa_updated
- 2026-03-03T21:31:58Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph