#VU125246 Improper access control in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to load untrusted plugins.
The vulnerability exists due to improper access control in the bundled plugin trust root configuration when loading an attacker-controlled workspace. A remote user can provide a workspace .env file that overrides OPENCLAW_BUNDLED_PLUGINS_DIR to load untrusted plugins.
Exploitation depends on the victim loading an attacker-controlled workspace.