logo

OpenClaw Flaws Expose Systems to Policy Bypass Attacks

ID: ef688c26-9ad4-516b-9fc0-2334dac71775

STIX ID: report--ef688c26-9ad4-516b-9fc0-2334dac71775

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Divya

...
...

OpenClaw released a security update (2026.4.20) addressing three moderate-severity vulnerabilities: a prompt-injection driven gateway configuration bypass that can alter trusted settings, bundled MCP/LSP tools that can evade final policy checks and remain available despite restrictive profiles, and a workspace.env override flaw (affecting versions 2026.4.5–2026.4.20) that can redirect MiniMax API requests and leak API keys. Administrators are strongly advised to upgrade immediately to protect configurations, API credentials, and agent safety policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.