logo

Multiple OpenClaw Vulnerabilities Enables Policy Bypass and Host Override

ID: d26342d6-ca82-5e55-a833-8657b8b81358

STIX ID: report--d26342d6-ca82-5e55-a833-8657b8b81358

Feed Name: cybersecurityNews.com

Threat Score
55/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Abinaya

...
...

Researchers disclosed three moderate-severity vulnerabilities in the OpenClaw AI agent framework (formerly Clawdbot/Moltbot) distributed via npm: a gateway configuration mutation that lets a model persistently alter operator-trusted settings, a bundled-tool policy-enforcement bypass that can activate tools after filtering, and a workspace host override that can redirect credentialed requests to attacker-controlled servers. The development team patched the issues in OpenClaw 2026.4.20 and recommends immediate upgrades to prevent credential exposure and local policy compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.