Incorrect Behavior Order: Validate Before Canonicalize in OpenClaw - CVE-2026-32033
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to validate-before-canonicalize behavior in tool path checks when processing @-prefixed absolute paths with workspace-only file-system restrictions enabled. A remote user can supply a specially crafted path to disclose sensitive information.
Only instances with non-default tools.fs.workspaceOnly=true configuration are vulnerable.