NVD HIGH: CVE-2026-100597 — OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-che...
OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem target after OpenClaw completed its sandbox path-safety check, if the path is changed concurrently. An attacker able to win the race can cause a sandboxed
CVE-2026-100597