Sandbox escape via TOCTOU race in remote FS bridge readFile
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.31121870a08583033ed6a0ed73d9ffea32991252bb — 2026-03-31T09:55:51+09:00OpenClaw thanks @AntAISecurityLab for reporting.
2026.3.31Exploitability
AV:NAC:LAT:NPR:LUI:NVulnerable System
VC:HVI:HVA:NSubsequent System
SC:HSI:HSA:H9.4/CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H