VDB
EN
HIGH 8.0

GHSA-474h-prjg-mmw3

OpenClaw: Sandboxed sessions_spawn(runtime="acp") bypassed sandbox inheritance and allowed host ACP initialization

상세

### Summary Sandboxed `sessions_spawn(runtime="acp")` could bypass sandbox inheritance and initialize host-side ACP runtime. The fix now fail-closes ACP spawn from sandboxed requester sessions and rejects `sandbox="require"` for `runtime="acp"`.

### Affected Packages / Versions - Package: `openclaw` (npm) - Latest published npm version at triage time: `2026.3.1` (March 2, 2026) - Vulnerable range: `<=2026.3.1` - Patched release: `2026.3.2` (released)

### Technical Details - Root cause: `runtime="subagent"` enforced sandbox inheritance, while `runtime="acp"` did not enforce equivalent sandbox/runtime checks. - Security impact: sandbox-boundary bypass into host-side ACP initialization. - Fixed behavior: - deny ACP spawn when requester runtime is sandboxed - deny `sessions_spawn` with `runtime="acp", sandbox="require"` - align sandboxed prompt guidance to avoid advertising blocked ACP paths

### Fix Commit(s) - `ac11f0af731d41743ba02d8595f4d0fe747336e3` - `c703aa0fe92df9fb71cf254fc46991e05fba2114`

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / openclaw
최초 영향 버전: 0 수정 버전: 2026.3.2
수정 npm install openclaw@2026.3.2

참고