Improper access control in OpenClaw - #VU132705
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to access owner-only MCP tools and disclose sensitive information.
The vulnerability exists due to improper access control in the hook ingress and bundled CLI backend selection when starting a hook-triggered automated agent run through the /hooks/agent endpoint with a valid hook token. A remote user can trigger a hook-initiated run that selects a bundled CLI backend to access owner-only MCP tools and disclose sensitive information.
Only deployments with hooks enabled are vulnerable.