CVE-2026-32988
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and popu
CVSS
7.5
High
EPSS
0.1%
p0
KEV
—
Exploit Today
0
0-100
Published: Mar 31, 2026 · Last modified: Jul 25, 2026 · CWE-367
0.1%EPSS · 30 days0.1%
2026-08-202026-09-17
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path before the final guarded replace step executes.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-252787.8 HIG0.4%
——0Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.19hCVE-2024-112226.4 MED20.7%
——6GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed a developer user to perform actions in the context of another user's merge request commit due to a race condition issue in pipeline creation.20hCVE-2026-917488.3 HIG11.8%
——4Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)20hCVE-2026-917445.3 MED13.4%
——4Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)1dCVE-2026-917438.3 HIG14.7%
——4Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)20hCVE-2026-917128.3 HIG16.6%
——5Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)20h