Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.31a30214a624946fc5c85c9558a27c1580172374fd — 2026-03-31T09:06:51+09:00OpenClaw thanks @AntAISecurityLab for reporting.
2026.3.31Exploitability
AV:NAC:LAT:PPR:LUI:NVulnerable System
VC:HVI:HVA:HSubsequent System
SC:HSI:HSA:H9.0/CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H