Sandbox escape via TOCTOU race in remote FS bridge readFile
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.31121870a08583033ed6a0ed73d9ffea32991252bb — 2026-03-31T09:55:51+09:00OpenClaw thanks @AntAISecurityLab for reporting.
{
"github_reviewed": true,
"github_reviewed_at": "2026-04-03T03:14:16Z",
"cwe_ids": [
"CWE-367"
],
"severity": "CRITICAL",
"nvd_published_at": "2026-04-21T00:16:29Z"
}