Improper Check or Handling of Exceptional Conditions in OpenClaw - #VU125245
Published: April 8, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to restore revoked Tlon configuration after restart.
The vulnerability exists due to improper handling of empty-array revocation settings in the startup migration logic when processing file-based configuration during startup. A local user can provide or rely on crafted file configuration state to restore revoked Tlon configuration after restart.