CVE-2026-100573
4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list and invoke denied tools to access data or perform actions the operator intended to exclude from the sandbox.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenClaw | OpenClaw | 0 < 2026.8.1 | affected |
| OpenClaw | OpenClaw | 2026.8.1 | unaffected |
Weaknesses
- CWE-862: Missing Authorization
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-5m4g-88rg-69pj
- https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-sandbox-policy-bypass-via-mcp-loopback
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.