OpenClaw 2026.3.28 patches 8 security vulnerabilities including critical privilege escalation

Critical security patches for OpenClaw
OpenClaw 2026.3.28 includes patches for 8 security vulnerabilities identified during a 3-day audit by Ant AI Security Lab. The audit found 33 issues total, with these 8 confirmed and fixed in the latest stable release.
Key vulnerabilities patched
The most significant issues include:
- Critical severity privilege escalation: Lower-privileged operators could approve admin access via the
/pair approvepath - High severity sandbox escape: The
messagetool could be tricked into reading arbitrary local files using alias parameters - High severity node pairing approval bypass
- High severity WebSocket session hijacking
Affected systems
These vulnerabilities affect multi-node OpenClaw setups and users of built-in tools like message or fal.
Security advisories
Detailed information is available in GitHub security advisories:
- Critical - /pair approve escalation: GHSA-hc5h-pmr3-3497
- High - message tool sandbox escape: GHSA-v8wv-jg3q-qwpq
- High - Node pairing approval bypass: GHSA-2x4x-cc5g-qmmg
- High - WebSocket session hijacking: GHSA-2pr2-hcv6-7gwv
Update to OpenClaw 2026.3.28 immediately if you haven't already.
📖 Read the full source: r/openclaw
👀 See Also

Google Says Criminal Hackers Used AI to Find Zero-Day Vulnerability
Google disclosed that attackers used an AI agent to discover and exploit a previously unknown software flaw, marking the first confirmed case of AI-driven zero-day discovery in the wild.

Microsoft's Open Source Tools Hacked: Password-Stealing Malware Hits AI Developer Repos
Hackers injected password-stealing malware into at least 70 Microsoft GitHub repos, targeting AI developers using Claude Code, Gemini CLI, and VS Code. This is a re-compromise of the earlier Durable Task breach.

Claude Code Plugin Bug Causes CPU Spikes and Battery Drain
A user discovered that Claude Code's Telegram plugin spawns multiple bun.exe processes that run at 100% CPU even with the laptop lid closed, causing rapid battery drain. The processes survive sleep/wake cycles and require specific cleanup steps to remove.

OpenClaw Security Audit Command Prompts Plain-English Vulnerability Reports
A Reddit user shared a prompt for the OpenClaw CLI that runs a deep security audit and outputs findings in plain English, specifying what's exposed, severity scores, and exact config fixes.