#VU125268 Improper access control in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to delete the contents of an unintended remote directory and replace them with uploaded workspace data.
The vulnerability exists due to improper access control in the OpenShell mirror backend when processing attacker-influenced remoteWorkspaceDir and remoteAgentWorkspaceDir values in mirror mode. A remote user can supply arbitrary absolute paths to trigger remote cleanup and overwrite operations to delete the contents of an unintended remote directory and replace them with uploaded workspace data.
Exploitation requires the ability to influence those OpenShell configuration values.