Executive brief
OpenClaw is an AI agent platform. A security flaw in its gateway component allows an AI model that has been manipulated via prompt injection to bypass safety restrictions and modify critical system settings. This could allow an attacker to disable security features like sandboxing, change authentication requirements, or alter filesystem protections, potentially leading to unauthorized access or persistent control over the environment.
Technical details
A missing authorization vulnerability (CWE-862) exists in the OpenClaw gateway's config.patch and config.apply endpoints. The 'guard' mechanism intended to restrict configuration changes failed to include several sensitive operator-trusted paths, such as sandbox policies, TLS settings, SSRF policies, and filesystem hardening. An attacker can exploit this by using a prompt-injected model that has access to the owner-only gateway tool to persist unauthorized configuration changes. This effectively allows a model-to-operator privilege escalation. The issue is resolved in version 2026.4.20 by expanding the mutation guard to cover these protected paths and per-agent overrides.
Affected products
- OpenClaw openclaw < 2026.4.20
Timeline
- 2026-04-21: advisory: GitHub Security Advisory published
- 2026-05-11: disclosed: NVD publication date
- 2026.4.20: patched: First patched version released