OpenClaw Update Fixes Prompt-Injection, Credential-Exposure and Other Security Flaws
OpenClaw is an AI agent framework that can connect to APIs, external tools and system credentials to perform multistep tasks on a user’s behalf. Because agents have elevated privileges, attackers could exploit prompt-injection or tool-management flaws to bypass security policies, manipulate execution flows or even steal sensitive data such as API keys. The update therefore addresses cybersecurity risks facing businesses that deploy AI agents.
OpenClaw recently released version 2026.4.20, addressing three key vulnerabilities: a prompt-injection bypass, a tool-registration flaw and malicious environment-variable injection. The update also strengthens permission management and system stability. OpenClaw urged users to upgrade as soon as possible to prevent API credentials from being exposed. It has not disclosed the number of affected users, any financial losses or cases in which the vulnerabilities were exploited.
All Coverage
2 original reportsThe Backstory
The history behind this eventOpenClaw Security Flaw Allows External Messages to Trigger Command Execution
Open-source AI agent integration platform OpenClaw is primarily used by businesses and developers to build automated workflows. It was recently found to contain serious flaws involving sandbox bypasses and environment-variable filtering. As generative AI adoption grows, the security of such integration platforms has become a major focus for the technology industry. If exploited, the vulnerability could expose corporate servers to remote control, posing a severe threat to information security and trade secrets.
Security researchers said in July 2026 that an attacker could bypass OpenClaw's defenses and execute arbitrary code on a host simply by sending an external WhatsApp message disguised as a debugging request. The OpenClaw development team mobilized urgently in response to the high-risk vulnerability and recently formally released version 2026.6.6 with a security patch. It urged all businesses and users running the platform to upgrade immediately.
Claw Chain Flaws in OpenClaw AI Agent Platform Allow Attackers to Plant Backdoors
OpenClaw is a platform that integrates AI agents with external tools. Its agents can typically access files, run programs and modify system settings, making sandbox isolation and permission controls especially important. Cybersecurity firm Cyera named the vulnerability chain Claw Chain. It involves file-system escape and privilege escalation flaws that attackers can combine to amplify the risk posed by any single weakness.
Cyera’s latest disclosure said attackers can chain multiple CVEs to execute code within the OpenClaw sandbox, then alter system configurations or plant malicious backdoors. The findings appeared in a May 18 cybersecurity incident roundup. The available information does not specify the CVE identifiers, affected versions, patch date or financial losses. Users should install updates in line with official advisories and check for anomalous settings.
OpenClaw 2026.5.3 Upgrade Enhances Real-Time AI Agent Intervention and Security
OpenClaw is an open-source platform for deploying and managing AI agents. In industrial and other settings involving continuously running tasks, an agent that cannot accept mid-process corrections may amplify operational and cybersecurity risks. Previous incidents involving malicious ClawHub plugins also made plugin supply-chain protection a key focus of this update.
OpenClaw released stable version 2026.5.3 on May 3, 2026, adding a /steer command that lets users intervene in an agent's work in real time and redirect it while it is running. The new version also restricts file transfers for nodes that have not completed pairing, while strengthening ClawHub plugin safeguards and security patches to reduce the risk of malware exploitation.
ClawJacked Flaw Leaves OpenClaw AI Agents Vulnerable to Remote Takeover
OpenClaw is an AI agent system that can perform tasks on a user’s computer. Because it can access local resources and carry out actions automatically, a hijacking would pose risks beyond the exposure of web data. Attackers could take control of the agent and potentially compromise device and account security.
Oasis Security disclosed ClawJacked, a high-risk vulnerability that allows a malicious website to bypass cross-origin policies through a WebSocket connection and remotely take over OpenClaw running on a computer. The security advisory was published on March 2, 2026. The development team has released patched version 2026.2.25 and urged users to update as soon as possible.
OpenClaw v2026.4.23 Adds GPT-image-2 OAuth Access and Three-Level Nested Subagents
OpenClaw is an open-source AI agent framework that coordinates models, tools and subagents to carry out complex tasks. The update integrates OpenAI’s image model and enhances collaboration among multiple layers of agents, reducing the burden of API-key management for developers and allowing lengthy workflows to be broken into smaller tasks. It also patches high-risk vulnerabilities, an important improvement for enterprise deployments and data security.
OpenClaw released v2026.4.23 on April 23, 2026, adding the ability to sign in through Codex OAuth and call OpenAI’s gpt-image-2 directly without entering a separate API key. Subagents can now be nested up to three levels deep and inherit conversation context from their parent agents. The release also patches several Critical-rated security vulnerabilities, strengthening protections for agent execution environments.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →