Executive brief
OpenClaw is a macOS desktop client that allows users to execute remote agent commands via deep links. A vulnerability in the confirmation dialog displays only the first 240 characters of a message to the user, but executes the full message after approval. An attacker could use whitespace padding to conceal malicious instructions, tricking users into executing unintended commands that could lead to arbitrary code execution.
Technical details
The vulnerability is a UI misrepresentation flaw (CWE-451) in OpenClaw's openclaw:// URL scheme handler. When processing unkeyed agent deep links, the confirmation dialog truncates the message display to 240 characters but fails to enforce the same limit on execution, creating a mismatch between what the user approves and what actually runs. An attacker can exploit this by padding the visible portion with whitespace to hide a malicious payload beyond the 240-character boundary, increasing the likelihood a user approves a different message than executed. This is a social-engineering attack vector requiring user interaction. The fix enforces strict message length limits for unkeyed deep links and restricts delivery/routing parameters to authenticated requests only.
Affected products
- OpenClaw macOS desktop client >= 2026.2.6, <= 2026.2.13
Timeline
- 2026-02-17: disclosed
- 2026-02-14: patched: Fixed in version 2026.2.14