Improper access control in OpenClaw - CVE-2026-32002
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the image tool when resolving sandbox mount paths with tools.fs.workspaceOnly=true. A remote user can load mounted out-of-workspace images and forward their contents to vision model providers to disclose sensitive information.
The issue affects mounted out-of-workspace files exposed through the sandbox FS bridge, such as /agent/*.