Multiple OpenClaw Vulnerabilities Enable Policy Bypass and Host Override Attacks
ID: eb3d3ef9-2002-5eb1-89f8-26dd7111926a
STIX ID: report--eb3d3ef9-2002-5eb1-89f8-26dd7111926a
Feed Name: Cyber Press
OpenClaw released security updates (2026.4.20) addressing three moderate-severity vulnerabilities in npm packages published before 2026.4.20: a prompt-injection-driven gateway configuration bypass that can override operator safeguards and modify sensitive settings; bundled MCP/LSP tools that could be added to an agent’s active toolset after filtering to bypass restrictions; and a credential-exposure flaw where a malicious .env can override MINIMAX_API_HOST and exfiltrate API keys. Administrators are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
