Observed Signal · Apr 2, 2026 · Vulnerability Disclosure · Source: DEV Community · Impact: 3/5 · Sentiment: Negative

OpenClaw SSH Sandbox Symlink Escape Vulnerability

Executive Signal Summary

A critical symbolic-link handling vulnerability (GHSA-FV94-QVG8-XQPW) was disclosed in the OpenClaw AI agent framework affecting versions 2026.3.28 and earlier. The flaw resides in the uploadDirectoryToSshTarget component and fails to validate symlinks before uploading, enabling an attacker interacting with an AI agent to traverse directory boundaries and perform arbitrary local file reads or arbitrary writes on remote SSH sandbox hosts. The issue carries a CVSS v3.1 score of 8.8 and is currently demonstrated by a proof-of-concept. The vulnerability was fixed in openclaw release 2026.3.31 (commit 3d5af14), which adds symlink validation via assertSafeUploadSymlinks and resolves boundary path checks. Recommended mitigations include upgrading to >=2026.3.31, enabling human-in-the-loop review, enforcing least-privilege SSH accounts, and implementing filesystem monitoring.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

High-severity sandbox escape in an AI agent framework (CVSS 8.8) can enable data exfiltration or remote compromise of environments where autonomous agents run; requires upgrades and operational mitigations across Node.js/npm deployments.

SIGNAL RADAR

Track NPM Capital Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Vulnerability ID GHSA-FV94-QVG8-XQPW disclosed for OpenClaw; CVSS v3.1 score 8.8.
  • Affected: openclaw npm package versions <= 2026.3.28; fixed in 2026.3.31 (commit 3d5af14).
  • Flaw in uploadDirectoryToSshTarget allows symlink traversal leading to arbitrary file read/write and sandbox escape.
  • Exploit status: Proof of Concept (academic).
  • Mitigations: upgrade to openclaw >=2026.3.31, enable human-in-the-loop, enforce least-privilege SSH, monitor filesystem for anomalous symlinks.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Apr 2, 2026
Original Coverage Title: “GHSA-FV94-QVG8-XQPW: GHSA-fv94-qvg8-xqpw: OpenClaw SSH Sandbox Symlink Escape and Arbitrary File Access”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Large Language Models (LLM) & AIFeb 2, 2026

OpenClaw Guide: Install Safely Amid Major Security Risks

A Product Compass guide describes OpenClaw, a viral always-on AI agent that runs across messaging apps and maintains persistent identity and memory. The author summarizes OpenClaw’s rapid growth (140K+ GitHub stars), the emergence of Moltbook (a social site for agents), and a recent Moltbook database leak exposing user emails and tokens. Through hands-on testing the author found a critical security issue: OpenClaw agents with shell access can disable their own safety guardrails and may be vulnerable to prompt-injection from user content. The guide recommends installing OpenClaw only in isolated environments, using dedicated accounts and API keys rather than personal tokens, and details tested hosting approaches (Docker, VPS, Cloudflare Workers) plus a step-by-step safe install workflow.

Read assessment
Large Language Models (LLM) & AIApr 14, 2026

OpenClaw on AWS Lightsail: Live Security Demo

A hands-on security analysis executed on April 14–15, 2026 documents deploying OpenClaw on an AWS Lightsail blueprint, the real installer steps missing from official docs, and practical attack vectors validated against an Anthropic Claude Sonnet 4.6 model via Amazon Bedrock. The report shows the blueprint provisions OpenClaw but not model access until an operator-run CloudShell script creates an IAM role to enable Bedrock. It demonstrates cross-account and cross-region inference complications (Control Tower GRREGIONDENY can block Bedrock routing), confirms several application+IaaS chained risks (sandbox disablement enabling web_fetch and cron persistence, filesystem-based memory poisoning, token exposure via SSH banner, unpatched kernel and Apache misconfiguration), and argues existing frameworks (MITRE ATLAS, OWASP, AWS scoping) fail to model the intersection of IaaS config and agent-layer vectors.

Read assessment
Large Language Models (LLM) & AIApr 27, 2026

Run OpenClaw in Windows Sandbox for Safe Isolation

A beginner-friendly Dev.to guide shows how to run the OpenClaw AI agent framework safely on a local Windows machine by using Windows Sandbox for disposable isolation. The article explains the primary risks of running agentic tools locally (file-system exposure, unrestricted internet and LAN access, prompt injection, secret leakage, and tool over-permissioning) and walks through a practical setup: enable Windows Sandbox, create an OpenClawSandbox.wsb file (example includes Networking Default and MemoryInMB), install Node.js (requires v22+, example uses v24.15.0), refresh PATH, allow PowerShell script execution for the session, install OpenClaw via npm, and run openclaw onboard (QuickStart). It also documents troubleshooting (persistence, resource tuning, npm/path issues, PowerShell execution policy, gateway "CIAO PROBING CANCELLED" and a recommended rollback to openclaw@2026.4.23) and notes Windows Sandbox deletes the session on close.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.