Input validation error in OpenClaw - CVE-2026-27159
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to cause increased resource consumption.
The vulnerability exists due to improper input validation in the tts model directive handling when processing model-generated TTS directives. A remote attacker can influence a reply to include a crafted provider override directive to cause increased resource consumption.
Exploitation requires multiple TTS providers to be configured.