logo

OpenClaw 2026.2.12 Released to Patch Over 40 Security Vulnerabilities

ID: 5e4943ef-3ea7-530e-84bd-993c005382b9

STIX ID: report--5e4943ef-3ea7-530e-84bd-993c005382b9

Feed Name: GBHackers

Threat Score
50/100

Date Published: 2026-02-13

Date Updated: 2026-04-22

Author: Divya

...
...

OpenClaw v2026.2.12 is a security- and stability-focused release that addresses over 40 issues: it hardens gateway URL handling against SSRF (deny policies and hostname allowlists for input_file/input_image), confines skill sync destinations to prevent path traversal, removes a bundled malicious hook component (`soul-evil`), fixes unauthenticated Nostr API config tampering, strips detailed tool results to reduce prompt-injection replay risks, tightens loopback/browser-control authentication, and includes integration-specific fixes for WhatsApp, Slack, and Signal; the release also introduces a breaking change disallowing sessionKey overrides by default.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.