CVE-2026-100573: OpenClaw before 2026.8.1 Sandbox Policy Bypass via MCP Loopback
OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list and invoke denied tools to access data or perform actions the operator intended to exclude from the sandbox.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.8.1
Event History
Frequently Asked Questions
Which deployments are exposed?
OpenClaw deployments running versions before 2026.8.1 are affected when they rely on sandbox.tools.deny to prevent sandboxed coding-agent sessions from accessing particular tools.
What access does an attacker need?
An attacker needs access to a sandboxed coding-agent session. No user interaction is required, and the supplied CVSS vector indicates local access and low privileges are required.
Can denied tools still be considered protected by the sandbox policy?
No. In affected versions, sandboxed sessions can list and invoke tools that were explicitly denied through sandbox.tools.deny, potentially accessing data or performing actions the operator intended to block.
What version should be deployed to address this issue?
Upgrade OpenClaw to version 2026.8.1 or later.