OpenClaw Flaws Expose Systems to Policy Bypass Attacks
ID: ef688c26-9ad4-516b-9fc0-2334dac71775
STIX ID: report--ef688c26-9ad4-516b-9fc0-2334dac71775
Feed Name: GBHackers
OpenClaw released a security update (2026.4.20) addressing three moderate-severity vulnerabilities: a prompt-injection driven gateway configuration bypass that can alter trusted settings, bundled MCP/LSP tools that can evade final policy checks and remain available despite restrictive profiles, and a workspace.env override flaw (affecting versions 2026.4.5–2026.4.20) that can redirect MiniMax API requests and leak API keys. Administrators are strongly advised to upgrade immediately to protect configurations, API credentials, and agent safety policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
