Signals

2026-07-27 / OpenClaw

OpenClaw's sandbox check returned success while the escape worked

Edited by Michael Ruescher

A path built from a symlinked subdirectory reads a planted sibling file while the sandbox assertion returns success. The fix is merged to main and is in no release on any channel; the maintainers describe it as defence in depth and state the check-to-use window remains open. Separately, the project's release page is not a reliable view of what installs: the npm tag serves an untagged respin with no git tag, no release, and no notes.

What this changes for operators

  • Do not treat the workspace boundary as a containment barrier on any current release, and resolve which build you are actually running from the package registry rather than the release page.

Featured in

Run: 2026-07-27-weekly-digest-2026-07-02_2026-07-27-frontier-v0

Schema: bitter.frontier_signals.v0 / ID: 2026-07-27-openclaw-sandbox-check-returns-success-while-escaping

Research evidence and publication history are open in the repository.