{"id":"GHSA-474h-prjg-mmw3","summary":"OpenClaw: Sandboxed sessions_spawn(runtime=\"acp\") bypassed sandbox inheritance and allowed host ACP initialization","details":"### Summary\nSandboxed `sessions_spawn(runtime=\"acp\")` could bypass sandbox inheritance and initialize host-side ACP runtime. The fix now fail-closes ACP spawn from sandboxed requester sessions and rejects `sandbox=\"require\"` for `runtime=\"acp\"`.\n\n### Affected Packages / Versions\n- Package: `openclaw` (npm)\n- Latest published npm version at triage time: `2026.3.1` (March 2, 2026)\n- Vulnerable range: `\u003c=2026.3.1`\n- Patched release: `2026.3.2` (released)\n\n### Technical Details\n- Root cause: `runtime=\"subagent\"` enforced sandbox inheritance, while `runtime=\"acp\"` did not enforce equivalent sandbox/runtime checks.\n- Security impact: sandbox-boundary bypass into host-side ACP initialization.\n- Fixed behavior:\n  - deny ACP spawn when requester runtime is sandboxed\n  - deny `sessions_spawn` with `runtime=\"acp\", sandbox=\"require\"`\n  - align sandboxed prompt guidance to avoid advertising blocked ACP paths\n\n### Fix Commit(s)\n- `ac11f0af731d41743ba02d8595f4d0fe747336e3`\n- `c703aa0fe92df9fb71cf254fc46991e05fba2114`","modified":"2026-03-04T15:11:35.777090Z","published":"2026-03-03T21:31:57Z","database_specific":{"github_reviewed_at":"2026-03-03T21:31:57Z","nvd_published_at":null,"cwe_ids":["CWE-269"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-474h-prjg-mmw3"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/commit/ac11f0af731d41743ba02d8595f4d0fe747336e3"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/commit/c703aa0fe92df9fb71cf254fc46991e05fba2114"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"}],"affected":[{"package":{"name":"openclaw","ecosystem":"npm","purl":"pkg:npm/openclaw"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2026.3.2"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2026.3.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-474h-prjg-mmw3/GHSA-474h-prjg-mmw3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}