#VU125212 Reliance on Untrusted Inputs in a Security Decision in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to bypass authorization controls.
The vulnerability exists due to reliance on untrusted inputs in a security decision in Google Chat group authorization when using mutable space display names for access decisions. A remote user can change or collide a space display name to bypass authorization controls.