highVulnerability
GHSA-7xmq-g46g-f8pv
### Summary Sandbox media handling had a time-of-check/time-of-use gap: media paths could be validated first and read later through a separate path. A symlink retarget between those steps could cause reads outside `sandboxRoot`. ### Impact Affected versions could permit host file reads outside the intended sandbox root in media attachment/image flows. ### Fix Media reads now use consolidated root-scoped, boundary-safe read paths at use time, removing check/use drift across call sites. ### Affected and Patched Versions - Affected: `<= 2026.2.26` - Patched: `2026.3.1`
Properties
- ghsa_id
- GHSA-7xmq-g46g-f8pv
- severity
- high
- summary
- OpenClaw: Sandbox media TOCTOU could read files outside sandbox root
- cve_id
- GHSA-7xmq-g46g-f8pv
- is_ghsa_only
- true
- ghsa_published
- 2026-03-02T21:55:47Z
- source_url
- https://github.com/advisories/GHSA-7xmq-g46g-f8pv
- ghsa_updated
- 2026-03-02T21:55:51Z
Related Entities (4)
AFFECTS (1)
→[Software]npm/OpenClaw
HAS_WEAKNESS (2)
→[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition
→[Weakness]Improper Link Resolution Before File Access ('Link Following')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph