Multiple OpenClaw Vulnerabilities Enables Policy Bypass and Host Override
ID: d26342d6-ca82-5e55-a833-8657b8b81358
STIX ID: report--d26342d6-ca82-5e55-a833-8657b8b81358
Feed Name: cybersecurityNews.com
Researchers disclosed three moderate-severity vulnerabilities in the OpenClaw AI agent framework (formerly Clawdbot/Moltbot) distributed via npm: a gateway configuration mutation that lets a model persistently alter operator-trusted settings, a bundled-tool policy-enforcement bypass that can activate tools after filtering, and a workspace host override that can redirect credentialed requests to attacker-controlled servers. The development team patched the issues in OpenClaw 2026.4.20 and recommends immediate upgrades to prevent credential exposure and local policy compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
