OpenClaw 2026.3.28 patches 8 security vulnerabilities including critical privilege escalation

Critical security patches for OpenClaw
OpenClaw 2026.3.28 includes patches for 8 security vulnerabilities identified during a 3-day audit by Ant AI Security Lab. The audit found 33 issues total, with these 8 confirmed and fixed in the latest stable release.
Key vulnerabilities patched
The most significant issues include:
- Critical severity privilege escalation: Lower-privileged operators could approve admin access via the
/pair approvepath - High severity sandbox escape: The
messagetool could be tricked into reading arbitrary local files using alias parameters - High severity node pairing approval bypass
- High severity WebSocket session hijacking
Affected systems
These vulnerabilities affect multi-node OpenClaw setups and users of built-in tools like message or fal.
Security advisories
Detailed information is available in GitHub security advisories:
- Critical - /pair approve escalation: GHSA-hc5h-pmr3-3497
- High - message tool sandbox escape: GHSA-v8wv-jg3q-qwpq
- High - Node pairing approval bypass: GHSA-2x4x-cc5g-qmmg
- High - WebSocket session hijacking: GHSA-2pr2-hcv6-7gwv
Update to OpenClaw 2026.3.28 immediately if you haven't already.
📖 Read the full source: r/openclaw
👀 See Also

OpenClaw Security Breach: CEO's Agent Sold for $25K, 135K Instances Exposed
A UK CEO's OpenClaw instance was sold for $25,000 on BreachForums, exposing plain-text Markdown files containing conversations, production databases, API keys, and personal details. SecurityScorecard found 135,000 OpenClaw instances exposed with insecure defaults.

OpenClaw Security Alert: 500,000 Public Instances, Default Config Exposes Systems
A security analysis reveals 500,000 OpenClaw instances are publicly accessible, with 30,000 having known security risks and 15,000 exploitable through known vulnerabilities. The default installation disables authentication and binds to 0.0.0.0, exposing agent setups to the open internet.

Open-source playground for red-teaming AI agents with published exploits
Fabraix has open-sourced a live environment to stress-test AI agent defenses through adversarial challenges. Each challenge deploys a live agent with real tools and published system prompts, with winning conversation transcripts and guardrail logs documented publicly.

Bitwarden Agent Access SDK integrates with OneCLI for secure credential injection
Bitwarden's new Agent Access SDK enables AI agents to access credentials from Bitwarden's vault with human approval, while OneCLI acts as a gateway that injects credentials at the network layer without exposing raw values to agents.