Insufficient verification of data authenticity in OpenClaw - #VU126840
Published: April 22, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to influence trust labeling of system awareness events.
The vulnerability exists due to improper trust labeling in cron awareness event handling when processing output from webhook-triggered isolated cron agent runs. A remote attacker can trigger an isolated cron run via a webhook to influence trust labeling of system awareness events.
This can strengthen prompt-injection impact, but it does not directly bypass gateway authentication, tool policy, or sandboxing.