#VU125261 Inclusion of Functionality from Untrusted Control Sphere in OpenClaw

 

#VU125261 Inclusion of Functionality from Untrusted Control Sphere in OpenClaw

Published: April 8, 2026


Vulnerability identifier: #VU125261
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-829
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
OpenClaw
Software vendor:
OpenClaw

Description

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to inclusion of functionality from an untrusted control sphere in built-in channel setup and login when resolving a workspace channel shadow that claims a bundled channel id before the plugin is explicitly trusted. A remote user can provide a crafted workspace plugin to execute arbitrary code.

Exploitation requires opening or using an untrusted cloned workspace, and the code may run even while the workspace plugin is still disabled.


Remediation

Install security update from vendor's website.

External links