OpenClaw 2026.2.12 Released to Patch Over 40 Security Vulnerabilities
ID: 5e4943ef-3ea7-530e-84bd-993c005382b9
STIX ID: report--5e4943ef-3ea7-530e-84bd-993c005382b9
Feed Name: GBHackers
OpenClaw v2026.2.12 is a security- and stability-focused release that addresses over 40 issues: it hardens gateway URL handling against SSRF (deny policies and hostname allowlists for input_file/input_image), confines skill sync destinations to prevent path traversal, removes a bundled malicious hook component (`soul-evil`), fixes unauthenticated Nostr API config tampering, strips detailed tool results to reduce prompt-injection replay risks, tightens loopback/browser-control authentication, and includes integration-specific fixes for WhatsApp, Slack, and Signal; the release also introduces a breaking change disallowing sessionKey overrides by default.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
