Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m6rx-7pvw-2f73 | OpenClaude: Sandbox Bypass via Early-Exit Logic Flaw Allows Path Traversal |
Thu, 23 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlawb:openclaude:*:*:*:*:*:*:*:* |
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitlawb
Gitlawb openclaude |
|
| Vendors & Products |
Gitlawb
Gitlawb openclaude |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Apr 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `bashToolHasPermission()` inside `src/tools/BashTool/bashPermissions.ts`. When the sandbox auto-allow feature is active and no explicit deny rule is configured, the function returns an `allow` result immediately — before the path constraint filter (`checkPathConstraints`) is ever evaluated. This allows commands containing path traversal sequences (e.g., `../../../../../etc/passwd`) to bypass directory restrictions entirely. Version 0.5.1 contains a patch for the issue. | |
| Title | OpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path Traversal | |
| Weaknesses | CWE-22 CWE-284 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-21T19:49:30.148Z
Reserved: 2026-04-03T20:09:02.826Z
Link: CVE-2026-35570
Updated: 2026-04-21T16:02:02.535Z
Status : Analyzed
Published: 2026-04-21T00:16:28.877
Modified: 2026-04-23T18:37:09.777
Link: CVE-2026-35570
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:47:08Z
Github GHSA