Junglewise Threat Intelligence

CVE-2026-27576: OpenClaw ACP uncontrolled resource consumption in local stdio bridge

CVE-2026-27576 · Severity: medium · CVSS 4 · Published 2026-02-20

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a development tool that integrates with IDEs and editors through a local stdio bridge for AI-powered code assistance. The ACP (Anthropic Communication Protocol) component fails to enforce prompt size limits, allowing very large text inputs to be forwarded to the chat service, causing degraded responsiveness, unexpected cost increases, and potential session instability for IDE users submitting unusually large code blocks or file contents.

Technical details

The vulnerability is an uncontrolled resource consumption issue (CWE-400) caused by missing input validation (CWE-20) in the ACP event-mapper and translator components. The ACP bridge accepts and concatenates arbitrarily large prompt text blocks without enforcing size limits before forwarding them to chat.send, allowing an attacker (or developer submitting large inputs locally) to assemble oversized payloads. Attack requires local access with ACP client capability (typically IDE plugins); remote exploitation is not possible in the default configuration. The fix enforces a 2 MiB prompt-text limit before concatenation and adds validation for inter-block separators and final outbound message size. Patches are available in versions 2026.2.18 and later.

Affected products

  • OpenClaw openclaw <= 2026.2.17

Timeline

  • 2026-02-20: disclosed: Advisory GHSA-cxpw-2g23-2vgw published
  • 2026-02-19: patched: Patch released in version 2026.2.19

References

Related threats