OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegistryEntry operations for sandbox containers and browsers. Attackers can exploit unsynchronized read-modify-write operations without locking to cause registry updates to lose data, resurrect removed entries, or corrupt sandbox state affecting list, prune, and recreate operations.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-19 22:16
Updated : 2026-03-20 13:39
NVD link : CVE-2026-32018
Mitre link : CVE-2026-32018
CVE.ORG link : CVE-2026-32018
JSON object : View
Products Affected
No product.
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
