#VU125108 Improper privilege management in OpenClaw - CVE-2026-32048
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to escape sandbox restrictions.
The vulnerability exists due to improper privilege management in sessions_spawn when creating cross-agent child sessions. A remote user can spawn a child under an agent configured with sandbox.mode="off" to escape sandbox restrictions.
Exploitation requires a mixed-agent setup that allows cross-agent spawning.