Inclusion of Functionality from Untrusted Control Sphere in OpenClaw - #VU128597
Published: April 30, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to auto-enable an untrusted provider plugin.
The vulnerability exists due to inclusion of functionality from an untrusted control sphere in workspace provider auth choices when performing non-interactive onboarding during auth setup. A remote user can shadow a provider auth choice with an untrusted workspace plugin to auto-enable an untrusted provider plugin.
Untrusted workspace choices are involved only when they are not explicitly enabled.