Inclusion of Functionality from Untrusted Control Sphere in OpenClaw - #VU135906
Published: June 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute or persist actions beyond the caller's intended authorization.
The vulnerability exists due to inclusion of functionality from untrusted control sphere in setup-mode discovery workspace plugins when processing a configured input path or lower-trust caller-controlled workspace input. A remote attacker can provide a crafted workspace plugin path or plugin input to execute or persist actions beyond the caller's intended authorization.
Only instances where the affected feature is enabled and reachable are vulnerable, and user interaction is required.