Inclusion of Functionality from Untrusted Control Sphere in OpenClaw - #VU125261

 

Inclusion of Functionality from Untrusted Control Sphere in OpenClaw - #VU125261

Published: April 8, 2026


Vulnerability identifier: #VU125261
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-829
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to inclusion of functionality from an untrusted control sphere in built-in channel setup and login when resolving a workspace channel shadow that claims a bundled channel id before the plugin is explicitly trusted. A remote user can provide a crafted workspace plugin to execute arbitrary code.

Exploitation requires opening or using an untrusted cloned workspace, and the code may run even while the workspace plugin is still disabled.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.4.2

External References

Related Security Bulletins