Skip to main content
Vulnerability Database/CVE-2026-100589

CVE-2026-100589: OpenClaw Sandbox Bypass Vulnerability

CVE-2026-100589 is a sandbox bypass flaw in OpenClaw that allows attackers to access paired node browser actions despite security restrictions. This post explains its technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-100589 Overview

CVE-2026-100589 is a sandbox bypass vulnerability affecting OpenClaw versions before 2026.7.1. The flaw resides in the browser tool and allows sandboxed sessions to reach paired node browser actions even when allowHostControl=false is configured. Attackers who control sandboxed agent input can select a paired node and invoke host browser operations against the connected profile. This exposes the authenticated browser state, including session cookies and stored credentials, to untrusted agent inputs. The vulnerability is classified under CWE-863: Incorrect Authorization.

Critical Impact

Sandboxed agents can inspect and manipulate an authenticated host browser profile, breaking the isolation boundary intended by allowHostControl=false.

Affected Products

  • OpenClaw versions prior to 2026.7.1
  • OpenClaw browser tool component
  • Deployments configured with allowHostControl=false relying on sandbox isolation

Discovery Timeline

  • 2026-09-26 - CVE-2026-100589 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-100589

Vulnerability Analysis

OpenClaw provides a browser tool that supports both sandboxed sessions and paired host nodes. The allowHostControl=false setting is intended to prevent sandboxed sessions from invoking host-side browser operations. The authorization check does not fully constrain which nodes a sandboxed session may target when invoking browser actions.

As a result, an attacker who can influence sandboxed agent input can direct the browser tool to a paired node that controls the host browser profile. The paired node then executes browser operations on behalf of the sandboxed session. This gives the attacker access to the authenticated state of the host browser, including cookies, local storage, and in some cases saved credentials.

The weakness aligns with [CWE-863], where the system performs an authorization check but fails to apply it to the full set of resources the actor can reach.

Root Cause

The browser tool enforces allowHostControl on direct host actions but not on paired node resolution. Sandbox-origin requests can resolve to a paired node identifier and inherit its privileges. The isolation boundary assumed by operators is therefore incomplete.

Attack Vector

Exploitation requires network reachability and low-privilege control over the agent input stream feeding a sandboxed session. No user interaction is required. The attacker crafts input that instructs the browser tool to target a paired node, then issues browser actions such as navigation, DOM inspection, or cookie extraction against the connected profile.

No verified public proof-of-concept code is available. Refer to the GitHub Security Advisory GHSA-9x88-f7rh and the Vulncheck Advisory for OpenClaw Sandbox Bypass for technical details.

Detection Methods for CVE-2026-100589

Indicators of Compromise

  • Browser tool invocations from sandboxed sessions that reference paired node identifiers when allowHostControl=false is set.
  • Host browser profile activity, including navigation and cookie reads, originating from agent sessions marked as sandboxed.
  • Unexpected authenticated requests from the host browser profile outside normal operator workflows.

Detection Strategies

  • Audit OpenClaw agent logs for cross-boundary tool calls that pair sandboxed session IDs with host node actions.
  • Correlate sandboxed session telemetry with host browser process events to identify boundary violations.
  • Baseline normal paired node usage and alert on sandboxed-origin requests invoking paired nodes.

Monitoring Recommendations

  • Enable verbose logging on the OpenClaw browser tool, including node selection and authorization decisions.
  • Forward agent and host browser telemetry to a central analytics platform for correlation across session boundaries.
  • Monitor outbound traffic from host browser profiles for anomalous authenticated API calls that may indicate session abuse.

How to Mitigate CVE-2026-100589

Immediate Actions Required

  • Upgrade OpenClaw to version 2026.7.1 or later on all deployments that use the browser tool.
  • Inventory all agent configurations that rely on allowHostControl=false as a security boundary and treat them as potentially bypassable until patched.
  • Rotate credentials and session cookies stored in host browser profiles that were reachable from sandboxed sessions.

Patch Information

The fix is included in OpenClaw 2026.7.1. See the GitHub Security Advisory GHSA-9x88-f7rh for the official vendor advisory and release details.

Workarounds

  • Disable paired node browser functionality for any agent configuration that also exposes sandboxed sessions until the upgrade is applied.
  • Separate host browser profiles from sandboxed agent workflows by running them on isolated hosts or user accounts.
  • Restrict network reachability to the OpenClaw control plane so only trusted operators can submit agent inputs.
bash
# Upgrade OpenClaw to the fixed release
pip install --upgrade "openclaw>=2026.7.1"

# Verify installed version
openclaw --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.