Improper access control in OpenClaw - #VU128584
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to load an untrusted plugin during channel setup.
The vulnerability exists due to improper access control in channel setup catalog lookups when resolving plugin entries. A remote user can introduce a workspace plugin shadow to load an untrusted plugin during channel setup.
The issue occurs because setup-time plugin loading can happen before the intended trust gate.