#VU125186 Reliance on Untrusted Inputs in a Security Decision in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to suppress dangerous-tool prompting.
The vulnerability exists due to reliance on untrusted inputs in a security decision in ACP permission resolution when processing conflicting tool identity hints from rawInput and metadata. A remote attacker can provide conflicting tool identity hints to suppress dangerous-tool prompting.