CVE-2026-100573 Overview
CVE-2026-100573 is a sandbox policy bypass vulnerability in OpenClaw versions before 2026.8.1. The flaw resides in the Model Context Protocol (MCP) loopback component. Sandboxed coding-agent sessions can enumerate and invoke tools that administrators explicitly denied through the sandbox.tools.deny policy. The weakness is classified as [CWE-862] Missing Authorization.
Attackers with local, low-privileged access to a sandboxed session can reach data or trigger actions the operator intended to exclude. The issue affects confidentiality within the sandbox boundary but does not directly impact integrity or availability.
Critical Impact
Sandboxed coding-agent sessions can bypass sandbox.tools.deny controls and invoke prohibited MCP tools, breaking the operator's intended isolation boundary.
Affected Products
- OpenClaw versions prior to 2026.8.1
- OpenClaw MCP loopback component
- Deployments relying on sandbox.tools.deny policy enforcement
Discovery Timeline
- 2026-09-26 - CVE-2026-100573 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100573
Vulnerability Analysis
OpenClaw sandboxes coding-agent sessions and restricts tool access using a policy file. The sandbox.tools.deny directive lists MCP tools that must not be exposed to the agent. The MCP loopback component fails to apply this deny list when the sandboxed session issues tool-listing or tool-invocation requests through the loopback channel.
As a result, an agent operating inside the sandbox can discover the full tool catalog and call entries the operator intended to block. The vulnerability is scoped to local attack surface, requires low privileges, and needs no user interaction. Impact is limited to confidentiality of data reachable through the denied tools.
Root Cause
The root cause is missing authorization enforcement in the MCP loopback request handler. The handler consults the sandbox session context but does not evaluate requests against the sandbox.tools.deny policy before resolving tool references or dispatching tool calls. Policy enforcement is applied on one request path but omitted on the loopback path, producing an inconsistent authorization model.
Attack Vector
An attacker who controls prompts, inputs, or code executed inside a sandboxed OpenClaw coding-agent session can issue MCP requests through the loopback interface. The attacker first calls the tool-listing endpoint to enumerate available tools, including those on the deny list. The attacker then invokes a denied tool directly through loopback to perform the restricted action or exfiltrate data accessible to that tool.
No authentication bypass or network access is required. The attack surface is limited to parties who can influence execution within an existing sandboxed session. See the GitHub Security Advisory GHSA-5m4g-88rg-69pj and the VulnCheck Advisory on OpenClaw for additional technical context.
Detection Methods for CVE-2026-100573
Indicators of Compromise
- MCP loopback requests from sandboxed sessions targeting tools listed in sandbox.tools.deny
- Tool-listing responses returning entries that should be filtered by policy
- Unexpected invocations of privileged or external-access tools from coding-agent sessions
Detection Strategies
- Log every MCP loopback request with session identifier, requested tool name, and policy decision
- Compare observed tool invocations against the configured sandbox.tools.deny list and alert on mismatches
- Baseline normal tool usage per project or agent profile and flag deviations
Monitoring Recommendations
- Forward OpenClaw sandbox and MCP loopback logs to a centralized analytics platform for correlation
- Alert on first-time use of sensitive tools (filesystem, network, shell) by any sandboxed session
- Review audit trails for enumeration patterns such as repeated tool-listing calls followed by denied-tool invocations
How to Mitigate CVE-2026-100573
Immediate Actions Required
- Upgrade OpenClaw to version 2026.8.1 or later on all hosts running coding-agent sandboxes
- Inventory existing sandbox policies and identify any sandbox.tools.deny entries that may have been bypassed
- Rotate credentials, tokens, or API keys that any denied tool could have accessed from a sandboxed session
Patch Information
The fix is included in OpenClaw 2026.8.1. Refer to the GitHub Security Advisory GHSA-5m4g-88rg-69pj for release notes and remediation guidance. The patched release enforces sandbox.tools.deny consistently across both standard and MCP loopback request paths.
Workarounds
- Restrict MCP loopback exposure to trusted components only, where feasible
- Remove sensitive tools from the sandbox entirely rather than relying solely on the deny list until patched
- Limit which users or processes can start sandboxed OpenClaw sessions to reduce local attack surface
# Verify installed OpenClaw version and upgrade
openclaw --version
# Upgrade to the patched release
pip install --upgrade "openclaw>=2026.8.1"
# Validate sandbox policy enforcement after upgrade
openclaw sandbox policy validate --config /etc/openclaw/sandbox.yaml
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.