Low severity3.3NVD Advisory· Published Sep 26, 2026
CVE-2026-100573
CVE-2026-100573
Description
OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list and invoke denied tools to access data or perform actions the operator intended to exclude from the sandbox.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.