Improper access control in OpenClaw - #VU132727
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass an approval step and apply a workshop change.
The vulnerability exists due to improper access control in the Skill Workshop apply flow when handling an agent tool call reaching the apply path. A remote attacker can trigger the affected apply path to bypass an approval step and apply a workshop change.
Only instances with the affected feature enabled and reachable are vulnerable, and user interaction is required.