highVulnerability

GHSA-7xmq-g46g-f8pv

### Summary Sandbox media handling had a time-of-check/time-of-use gap: media paths could be validated first and read later through a separate path. A symlink retarget between those steps could cause reads outside `sandboxRoot`. ### Impact Affected versions could permit host file reads outside the intended sandbox root in media attachment/image flows. ### Fix Media reads now use consolidated root-scoped, boundary-safe read paths at use time, removing check/use drift across call sites. ### Affected and Patched Versions - Affected: `<= 2026.2.26` - Patched: `2026.3.1`

Properties

ghsa_id
GHSA-7xmq-g46g-f8pv
severity
high
summary
OpenClaw: Sandbox media TOCTOU could read files outside sandbox root
cve_id
GHSA-7xmq-g46g-f8pv
is_ghsa_only
true
ghsa_published
2026-03-02T21:55:47Z
source_url
https://github.com/advisories/GHSA-7xmq-g46g-f8pv
ghsa_updated
2026-03-02T21:55:51Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition
[Weakness]Improper Link Resolution Before File Access ('Link Following')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph