Code Injection in OpenClaw - #VU128815
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to execute unintended JavaScript.
The vulnerability exists due to improper control of code generation in webhook transform module import handling when resolving a transform module path through a symlinked entry outside the trusted transform directory. A remote user can cause the gateway to dynamically import attacker-controlled code to execute unintended JavaScript.
Exploitation requires hook transforms to be enabled and reachable, influence over transform path resolution, and a symlink escape to attacker-controlled code.