Input validation error in OpenClaw - #VU126439
Published: April 17, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to inject untrusted input into trusted system event context.
The vulnerability exists due to improper input validation in agent hook event dispatch when processing externally supplied hook metadata. A remote attacker can supply crafted hook metadata to inject untrusted input into trusted system event context.