CVE-2026-100573: OpenClaw before 2026.8.1 Sandbox Policy Bypass via MCP Loopback

Published Sep 26, 2026
·
Updated

OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list and invoke denied tools to access data or perform actions the operator intended to exclude from the sandbox.

Affected Software

1 affected component
OpenClaw OpenClaw<2026.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenClaw to a version that resolves this vulnerability.

    Fixed in 2026.8.1

Event History

Sep 26, 2026
CVE Published
via MITRE·02:19 AM
Data Sourced
via MITRE·02:19 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

OpenClaw deployments running versions before 2026.8.1 are affected when they rely on sandbox.tools.deny to prevent sandboxed coding-agent sessions from accessing particular tools.

2

What access does an attacker need?

An attacker needs access to a sandboxed coding-agent session. No user interaction is required, and the supplied CVSS vector indicates local access and low privileges are required.

3

Can denied tools still be considered protected by the sandbox policy?

No. In affected versions, sandboxed sessions can list and invoke tools that were explicitly denied through sandbox.tools.deny, potentially accessing data or performing actions the operator intended to block.

4

What version should be deployed to address this issue?

Upgrade OpenClaw to version 2026.8.1 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203