CVE-2026-32048: Openclaw

Critical severity, CVSS 9.9. EPSS: 0.4% chance of exploitation in the next 30 days.

OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to create child processes under unsandboxed agents. An attacker with a sandboxed session can exploit this to spawn child runtimes with sandbox.mode set to off, bypassing runtime confinement restrictions.

Affected products

  • Openclaw Openclaw: before 2026.3.1 (fixed in 2026.3.1)

Published 2026-03-21. Last modified 2026-06-17.