Executive brief
OpenClaw, an automated agent platform, contains a flaw where certain automated tasks (triggered via hooks) can gain unauthorized administrative access. An attacker with a valid hook token could execute commands with the full privileges of the system owner, potentially allowing them to modify sensitive configurations or access restricted tools. This could lead to unauthorized data access or persistent changes to the system's operational state.
Technical details
A privilege escalation vulnerability exists in OpenClaw where hook-triggered agent runs can be assigned owner-scoped Model Context Protocol (MCP) loopback authority. The issue occurs when a hook ingress starts an automated run that selects a bundled CLI backend; the system fails to properly restrict the scope of the resulting runtime to the hook's intended permissions. An attacker possessing a valid hook token can exploit this to access or execute MCP tools that are restricted to the system owner, such as modifying persistent cron states. This vulnerability is fixed in version 2026.5.20.
Affected products
- openclaw openclaw < 2026.5.20
Timeline
- 2026-05-28: disclosed
- 2026-06-11: advisory: NVD publication date
- 2026-07-02: patched: GitHub Advisory published/updated