CVE-2026-32918

OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or sibling session state. Attackers can supply arbitrary sessionKey values to read or modify session data outside their sandbox scope, including persisted model overrides.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-29 13:17

Updated : 2026-03-30 13:26


NVD link : CVE-2026-32918

Mitre link : CVE-2026-32918

CVE.ORG link : CVE-2026-32918


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization