Inclusion of Functionality from Untrusted Control Sphere in OpenClaw - #VU125261

 

Inclusion of Functionality from Untrusted Control Sphere in OpenClaw - #VU125261

Published: April 8, 2026


Vulnerability identifier: #VU125261
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-829
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: OpenClaw
Affected software:
OpenClaw

Detailed vulnerability description

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to inclusion of functionality from an untrusted control sphere in built-in channel setup and login when resolving a workspace channel shadow that claims a bundled channel id before the plugin is explicitly trusted. A remote user can provide a crafted workspace plugin to execute arbitrary code.

Exploitation requires opening or using an untrusted cloned workspace, and the code may run even while the workspace plugin is still disabled.


Remediation

Install security update from vendor's website.

Sources