Incorrect authorization in OpenClaw - #VU128590
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to write files outside the intended workspace boundary.
The vulnerability exists due to incorrect authorization in screen_record outPath handling when processing an authorized tool call with an outPath value. A remote user can supply an outPath outside the workspace guard to write files outside the intended workspace boundary.