OpenClaw's sandbox check returned success while the escape worked
A path built from a symlinked subdirectory reads a planted sibling file while the sandbox assertion returns success. The fix is merged to main and is in no release on any channel; the maintainers describe it as defence in depth and state the check-to-use window remains open. Separately, the project's release page is not a reliable view of what installs: the npm tag serves an untagged respin with no git tag, no release, and no notes.
What this changes for operators
- Do not treat the workspace boundary as a containment barrier on any current release, and resolve which build you are actually running from the package registry rather than the release page.
Featured in
- Assume the Rule Does Not Bind / 2026-07-27
Run: 2026-07-27-weekly-digest-2026-07-02_2026-07-27-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-07-27-openclaw-sandbox-check-returns-success-while-escaping
Research evidence and publication history are open in the repository.