Improper access control in OpenClaw - #VU128794
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to initiate unintended agent actions.
The vulnerability exists due to improper access control in the openclaw://agent deep-link handler when processing crafted deep links on iOS. A remote attacker can send a specially crafted deep link to initiate unintended agent actions.
User interaction is required to open the crafted deep link, and exploitation is limited to an already-connected iOS node context.