GHSA-mj4p-rc52-m843: OpenClaw: Sandbox staged writes could escape the verified parent directory before commit
In affected versions of openclaw, sandbox fs-bridge writes validated the destination before commit, but temporary file creation and population were not pinned to a verified parent directory. A raced parent-path alias change could cause the staged temp file to be created outside the intended writable mount before the final guarded replace step.
References
Code Behaviors & Features
Detect and mitigate GHSA-mj4p-rc52-m843 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →