OpenClaw Security Vulnerabilities: Critical Framework Flaws Patched in 2026.3.28

✍️ OpenClawRadar📅 Published: April 1, 2026🔗 Source
OpenClaw Security Vulnerabilities: Critical Framework Flaws Patched in 2026.3.28
Ad

Critical Security Vulnerabilities in OpenClaw Framework

Ant AI Security Lab conducted a 3-day audit of OpenClaw's core framework and submitted 33 vulnerability reports. Eight of these vulnerabilities were patched in the 2026.3.28 release, revealing significant architectural security issues beyond the commonly discussed prompt injection and malicious skill risks.

Specific Vulnerabilities Identified

  • Sandbox Bypass via Tool Parameters: In versions <= 2026.3.24, the message tool accepts mediaUrl and fileUrl aliases that bypass sandbox validation. This allows agents constrained to a sandbox to read arbitrary local files through these alias parameters, effectively breaking isolation.
  • Privilege Escalation via Device Pairing: The /pair approve command path was calling device approval without forwarding caller scopes into the core check. Users with basic pairing privileges could approve pending device requests asking for broader scopes, including full admin access, granting themselves permissions they don't have.
  • Session Persistence After Token Revocation: When tokens are revoked, the gateway only updates stored credentials without disconnecting already-authenticated WebSocket sessions. Revoked devices can continue using their live sessions until connections naturally drop.
  • SSRF Vulnerability in Image Provider: The fal provider for image generation uses raw fetches for both API traffic and image downloads, skipping SSRF-guarded fetch paths. Malicious relays could force the gateway to fetch internal URLs and expose internal service responses through the image pipeline.
  • Allowlist Degradation: Route-level group allowlists (e.g., for Google Chat or Zalo) were silently downgrading from allowlist to open instead of preserving group policies. Any member of the allowlisted space could interact with the bot, ignoring sender-level restrictions.
Ad

Immediate Actions Required

  • Check your OpenClaw version. If it's < 2026.3.28, update immediately.
  • Review pairing logs for any unexpected admin grants.
  • If you recently revoked a token, force-restart your gateway to kill lingering WebSocket sessions.

The Ant AI Security Lab audit highlights that while much attention focuses on LLM behavior, the underlying framework's trust boundaries and parameter validation are equally critical for security. All 8 advisories from the audit are publicly available on the OpenClaw GitHub security tab.

📖 Read the full source: r/openclaw

Ad

👀 See Also

SCION: Switzerland's Secure Alternative to BGP Routing Protocol
Security

SCION: Switzerland's Secure Alternative to BGP Routing Protocol

SCION (Scalability, Control, and Isolation On Next-Generation Networks) is an internet routing architecture developed at ETH Zürich that replaces BGP's foundation with built-in security and multi-path routing. Unlike BGP patches like RPKI and BGPsec, SCION establishes tens or hundreds of parallel paths with millisecond rerouting when failures occur.

OpenClawRadar
AI Agent Exploits SQL Injection to Compromise McKinsey's Lilli Chatbot
Security

AI Agent Exploits SQL Injection to Compromise McKinsey's Lilli Chatbot

Security researchers at CodeWall used an autonomous AI agent to hack McKinsey's internal Lilli chatbot, gaining full read-write access to its production database in two hours via an SQL injection vulnerability in unauthenticated API endpoints.

OpenClawRadar
Free Claude Skill Scans Other Skills for Security Risks
Security

Free Claude Skill Scans Other Skills for Security Risks

A developer has built a free Claude skill that reviews the security of other Claude skills by checking code for potentially malicious behavior and analyzing repositories with a scorecard-style approach. The tool helps answer whether a Claude skill appears reasonably safe to use.

OpenClawRadar
Clawvisor: Purpose-Based Authorization Layer for OpenClaw Agents
Security

Clawvisor: Purpose-Based Authorization Layer for OpenClaw Agents

Clawvisor is an authorization layer that sits between AI agents and APIs, enforcing purpose-based authorization where agents declare intentions, users approve specific purposes, and an AI gatekeeper verifies every request against that purpose. Credentials never leave Clawvisor and agents never see them.

OpenClawRadar