Input validation error in OpenClaw - #VU132768
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to cause incorrect group-policy decisions for a tool invocation.
The vulnerability exists due to improper input validation in the group policy resolver when processing a supplied group id. A remote user can supply an unvalidated group id to cause incorrect group-policy decisions for a tool invocation.
Only deployments where the affected feature is enabled and reachable are exposed.