rootpwn

medium · CVSS v3 3.3 · CVSS v4 4.8 · EPSS 0.00107

CVE-2026-100573

OpenClaw versions prior to 2026.8.1 have a sandbox policy bypass in the MCP loopback component, allowing sandboxed coding-agent sessions to

Overview

OpenClaw versions prior to 2026.8.1 have a sandbox policy bypass in the MCP loopback component, allowing sandboxed coding-agent sessions to invoke tools that are explicitly denied by the sandbox.tools.deny policy. This flaw enables attackers to list and execute prohibited tools, potentially exposing sensitive data or performing unintended actions. The vulnerability is rated medium severity with a CVSS v3 score of 3.3.

Description

OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list and invoke denied tools to access data or perform actions the operator intended to exclude from the sandbox.

Impact

Confidentiality: attackers can access data exposed by denied tools. Integrity: they can perform actions the operator intended to block. Availability: not directly impacted. Defenders: system administrators and operators of OpenClaw environments.

Remediation

Apply the 2026.8.1 patch or later to fix the sandbox policy bypass. Verify that sandbox.tools.deny policies are correctly configured and enforce the intended restrictions. Enable logging of tool invocation attempts and regularly audit logs for unauthorized activity.

Risk context

The vulnerability has a medium severity rating (CVSS v3 3.3) and a very low EPSS score of 0.00107, indicating a low likelihood of exploitation in the wild. Nonetheless, defenders should prioritize patching to 2026.8.1 or later and validate sandbox configurations promptly.

Affected products

  • OpenClaw

Scores

Severity
medium
CVSS v2
1.7
CVSS v3
3.3
CVSS v4
4.8
EPSS
0.00107

sandbox policy-bypass OpenClaw medium-severity MCP denied-tools patch

← All CVEs