Impact
OpenClaw before 2026.8.1 does not correctly enforce sender tool policies when generating session‑memory filenames. The filename generator can create an embedded helper that retains tools removed by the originating sender's policy. When a model processes a model‑mediated instruction, the helper can invoke tools outside the sender's effective policy, leading to the creation of persistent scheduled work. This flaw allows actors using lower‑trust senders to bypass tool restrictions and run unintended commands, compromising the integrity of the system's operation.
Affected Systems
The vulnerability affects the npm package openclaw in all releases prior to 2026.8.1. No specific sub‑version list is provided beyond the run‑before‑2026.8.1 range, so any installation of openclaw older than 2026.8.1 is considered vulnerable.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting exposure risk may vary. The likely attack vector is injection of instructions via a model that has access to lower‑trust senders; exploitation requires the model to act on the injected instruction and the helper to expose the forbidden tools. The issue is resolved in 2026.8.1. Until the update can be applied, disabling session‑memory filename generation for agents reachable by lower‑trust senders is an available workaround.
OpenCVE Enrichment