highCVSS 8.1Vulnerability

GHSA-474h-prjg-mmw3

### Summary Sandboxed `sessions_spawn(runtime="acp")` could bypass sandbox inheritance and initialize host-side ACP runtime. The fix now fail-closes ACP spawn from sandboxed requester sessions and rejects `sandbox="require"` for `runtime="acp"`. ### Affected Packages / Versions - Package: `openclaw` (npm) - Latest published npm version at triage time: `2026.3.1` (March 2, 2026) - Vulnerable range: `<=2026.3.1` - Patched release: `2026.3.2` (released) ### Technical Details - Root cause: `runtime="subagent"` enforced sandbox inheritance, while `runtime="acp"` did not enforce equivalent sandbox/runtime checks. - Security impact: sandbox-boundary bypass into host-side ACP initialization. - Fixed behavior: - deny ACP spawn when requester runtime is sandboxed - deny `sessions_spawn` with `runtime="acp", sandbox="require"` - align sandboxed prompt guidance to avoid advertising blocked ACP paths ### Fix Commit(s) - `ac11f0af731d41743ba02d8595f4d0fe747336e3` - `c703aa0fe92df9fb71cf254fc46991e05fba2114`

Properties

ghsa_id
GHSA-474h-prjg-mmw3
severity
high
summary
OpenClaw: Sandboxed sessions_spawn(runtime="acp") bypassed sandbox inheritance and allowed host ACP initialization
cvss_score
8.1
cve_id
GHSA-474h-prjg-mmw3
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-03-03T21:31:57Z
source_url
https://github.com/advisories/GHSA-474h-prjg-mmw3
ghsa_updated
2026-03-03T21:31:58Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Improper Privilege Management

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-474h-prjg-mmw3 (CVSS 8.1) — Ninja Signal Threat Intelligence | Ninja Signal