medium · CVSS v3 3.3 · CVSS v4 4.8 · EPSS 0.00107
CVE-2026-100573
OpenClaw versions prior to 2026.8.1 have a sandbox policy bypass in the MCP loopback component, allowing sandboxed coding-agent sessions to
Overview
OpenClaw versions prior to 2026.8.1 have a sandbox policy bypass in the MCP loopback component, allowing sandboxed coding-agent sessions to invoke tools that are explicitly denied by the sandbox.tools.deny policy. This flaw enables attackers to list and execute prohibited tools, potentially exposing sensitive data or performing unintended actions. The vulnerability is rated medium severity with a CVSS v3 score of 3.3.
Description
OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list and invoke denied tools to access data or perform actions the operator intended to exclude from the sandbox.
Impact
Confidentiality: attackers can access data exposed by denied tools. Integrity: they can perform actions the operator intended to block. Availability: not directly impacted. Defenders: system administrators and operators of OpenClaw environments.
Remediation
Apply the 2026.8.1 patch or later to fix the sandbox policy bypass. Verify that sandbox.tools.deny policies are correctly configured and enforce the intended restrictions. Enable logging of tool invocation attempts and regularly audit logs for unauthorized activity.
Risk context
The vulnerability has a medium severity rating (CVSS v3 3.3) and a very low EPSS score of 0.00107, indicating a low likelihood of exploitation in the wild. Nonetheless, defenders should prioritize patching to 2026.8.1 or later and validate sandbox configurations promptly.
Affected products
- OpenClaw
Scores
- Severity
- medium
- CVSS v2
- 1.7
- CVSS v3
- 3.3
- CVSS v4
- 4.8
- EPSS
- 0.00107