#VU125106 Improper Handling of Unicode Encoding in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to bypass command policy restrictions.
The vulnerability exists due to improper handling of unicode encoding in node metadata policy classification when processing paired node metadata. A remote user can supply unicode-confusable platform or deviceFamily metadata to bypass command policy restrictions.
The issue occurs within the paired-node trust boundary and can broaden default node command allowlists.