Incomplete List of Disallowed Inputs in OpenClaw - #VU132692
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to trigger unintended wrapper-level side effects.
The vulnerability exists due to incomplete neutralization of special elements in the exec allowlist path when processing command requests through transparent command wrappers. A remote user can submit a crafted command request to trigger unintended wrapper-level side effects.
Exploitation requires the affected feature to be enabled and reachable, and practical impact depends on whether lower-trust input can reach that path.