OpenClaw: Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation
Description
Published to the GitHub Advisory Database
Apr 2, 2026
Reviewed
Apr 2, 2026
Last updated
Apr 2, 2026
Summary
Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation
Current Maintainer Triage
Affected Packages / Versions
openclaw(npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.31Fix Commit(s)
a30214a624946fc5c85c9558a27c1580172374fd— 2026-03-31T09:06:51+09:00OpenClaw thanks @AntAISecurityLab for reporting.
References