OpenClaw 2026.5.3 Upgrade Enhances Real-Time AI Agent Intervention and Security
OpenClaw is an open-source platform for deploying and managing AI agents. In industrial and other settings involving continuously running tasks, an agent that cannot accept mid-process corrections may amplify operational and cybersecurity risks. Previous incidents involving malicious ClawHub plugins also made plugin supply-chain protection a key focus of this update.
OpenClaw released stable version 2026.5.3 on May 3, 2026, adding a /steer command that lets users intervene in an agent's work in real time and redirect it while it is running. The new version also restricts file transfers for nodes that have not completed pairing, while strengthening ClawHub plugin safeguards and security patches to reduce the risk of malware exploitation.
All Coverage
1 original reportsThe Backstory
The history behind this eventOpenClaw 2.0 Adds Guided AI Setup, 575-Millisecond Control UI
OpenClaw is an open-source tool designed to coordinate AI-agent workflows across models and computing environments. Version 2.0 aims to lower the setup barrier by supporting ChatGPT, Claude and llama.cpp through a guided configuration flow that can detect locally stored AI credentials and available models. The release also adopts one trust boundary per Gateway, an architecture intended to isolate permissions while supporting broader agent deployment.
Released after roughly two months of development, OpenClaw 2.0 introduces a rebuilt browser-based control interface that starts in 575 milliseconds. The platform now combines file editing with Git change tracking and expands support for shared sessions, cross-device work and cloud-based agents. Those additions allow team members to take over existing tasks more directly, extending the product beyond installation improvements into collaborative agent operations.
OpenClaw Update Fixes Prompt-Injection, Credential-Exposure and Other Security Flaws
OpenClaw is an AI agent framework that can connect to APIs, external tools and system credentials to perform multistep tasks on a user’s behalf. Because agents have elevated privileges, attackers could exploit prompt-injection or tool-management flaws to bypass security policies, manipulate execution flows or even steal sensitive data such as API keys. The update therefore addresses cybersecurity risks facing businesses that deploy AI agents.
OpenClaw recently released version 2026.4.20, addressing three key vulnerabilities: a prompt-injection bypass, a tool-registration flaw and malicious environment-variable injection. The update also strengthens permission management and system stability. OpenClaw urged users to upgrade as soon as possible to prevent API credentials from being exposed. It has not disclosed the number of affected users, any financial losses or cases in which the vulnerabilities were exploited.
OpenClaw Releases v2026.5.4 With Gemini Voice Agent Support and Prompt Cache Fix
OpenClaw, an open-source AI agent framework popularly known in its community as “Lobster,” connects large language models with messaging platforms, allowing automated assistants to be deployed in everyday conversations. The update matters because voice interaction and Prompt Cache cost controls directly affect how agents are used, API spending and service stability.
OpenClaw released the medium-sized v2026.5.4 update on May 4, 2026, adding a Gemini voice bridge that enables AI agents to make voice calls. It also fixed a Prompt Cache issue to prevent cache failures from causing API costs to surge, though the project did not disclose specific savings. The release also improves WhatsApp, Telegram and Discord functionality and strengthens several security safeguards.
ClawJacked Flaw Leaves OpenClaw AI Agents Vulnerable to Remote Takeover
OpenClaw is an AI agent system that can perform tasks on a user’s computer. Because it can access local resources and carry out actions automatically, a hijacking would pose risks beyond the exposure of web data. Attackers could take control of the agent and potentially compromise device and account security.
Oasis Security disclosed ClawJacked, a high-risk vulnerability that allows a malicious website to bypass cross-origin policies through a WebSocket connection and remotely take over OpenClaw running on a computer. The security advisory was published on March 2, 2026. The development team has released patched version 2026.2.25 and urged users to update as soon as possible.
OpenClaw v2026.4.23 Adds GPT-image-2 OAuth Access and Three-Level Nested Subagents
OpenClaw is an open-source AI agent framework that coordinates models, tools and subagents to carry out complex tasks. The update integrates OpenAI’s image model and enhances collaboration among multiple layers of agents, reducing the burden of API-key management for developers and allowing lengthy workflows to be broken into smaller tasks. It also patches high-risk vulnerabilities, an important improvement for enterprise deployments and data security.
OpenClaw released v2026.4.23 on April 23, 2026, adding the ability to sign in through Codex OAuth and call OpenAI’s gpt-image-2 directly without entering a separate API key. Subagents can now be nested up to three levels deep and inherit conversation context from their parent agents. The release also patches several Critical-rated security vulnerabilities, strengthening protections for agent execution environments.
OpenClaw Releases 2026.3.28 Update With xAI Search and AI Plugin Approval Controls
OpenClaw is a system that uses AI agents to operate tools and run workflows across communication platforms. Agents can invoke plugins autonomously, but that capability also raises the risk of errors or unauthorized actions. The addition of human approval checkpoints allows high-risk plugin operations to be confirmed before an agent proceeds.
OpenClaw released version 2026.3.28 on March 28, 2026, ahead of ClawCon in Tokyo, introducing “plugin approval hooks.” The update also integrates the xAI Responses API to give Grok search capabilities and improves workspace binding for Discord and iMessage.
Taiwan Cybersecurity Agency Urges Five Safeguards for OpenClaw Adoption
OpenClaw is an open-source AI agent that can be deployed on a local server or personal computer and connected to large language models, APIs and instant-messaging platforms to autonomously manage schedules, messages, files and code. Taiwan’s Administration for Cyber Security under the Ministry of Digital Affairs said OpenClaw has extensive system privileges and can operate around the clock. If compromised, it could expose login credentials, personal information and financial data, with potential repercussions for corporate internal networks.
On March 25, 2026, the agency advised organizations adopting OpenClaw to implement five safeguards: isolate its operating environment, use least-privilege accounts, require human review for high-risk actions, inspect third-party Skills before installation, and write security rules into its core memory. The warning cited no financial figures and focused on reducing the risks of AI agents losing control, exceeding their authorization and leaking data.
Open-Source AI Agent Platform OpenClaw Releases v2026.3.22 With GPT-5.4 Support
OpenClaw is an open-source AI agent platform that uses models, tools and plugins to automate multistep tasks. The update focuses on long-running jobs, isolated execution environments and model compatibility, reflecting AI agents' shift from brief question-and-answer interactions toward continuously operating workflows.
OpenClaw's latest release, versioned v2026.3.22 after March 22, 2026, launches the ClawHub plugin marketplace and adds full support for GPT-5.4, SSH sandboxes and sessions lasting up to 48 hours. However, community reports indicate that the new version may not include the console, potentially leaving existing users without access to the interface after upgrading. Users should check the official guidance before updating.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →