#VU125171 Incorrect authorization in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to incorrect authorization in the image tool path resolution when processing image paths with tools.fs.workspaceOnly enabled. A remote attacker can supply a crafted image path to disclose sensitive information.
The issue affects access to sandbox bridge mounts outside the workspace that other file tools would reject.