Incorrect authorization in OpenClaw - CVE-2026-32007
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to access and modify mounted paths outside the workspace root.
The vulnerability exists due to improper access control in the experimental apply_patch tool when processing patch operations on sandbox-resolved mounted paths. A remote user can submit a specially crafted patch targeting writable mounted paths outside the workspace root to access and modify mounted paths outside the workspace root.
This issue affects only opt-in sandbox configurations where sandbox mode, the experimental apply_patch tool, workspace-only expectations, and writable mounts outside the workspace are enabled.