Executive brief
OpenClaw is an automation platform that uses agents to perform scheduled tasks. A vulnerability in how the system labels data from these tasks allows untrusted information from external webhooks to be incorrectly marked as a trusted system event. This could allow an attacker to more effectively manipulate the AI's behavior through prompt injection, potentially leading to unauthorized actions or data exposure.
Technical details
OpenClaw before version 2026.4.20 contains a trust-labeling vulnerability (CWE-345) in its cron agent component. The software fails to maintain 'untrusted' labels when promoting isolated cron awareness summaries into the main session awareness stream. An attacker can trigger webhooks that feed data into these cron agents, causing the resulting output to be rendered as a 'System' event rather than an untrusted event. This misclassification can be leveraged to strengthen prompt-injection attacks by making malicious instructions appear to the LLM as authoritative system commands. The issue is fixed in version 2026.4.20 by ensuring the trust flag is forwarded through cron delivery helpers.
Affected products
- OpenClaw openclaw < 2026.4.20
Timeline
- 2026-04-21: advisory: Original advisory GHSA-57r2-h2wj-g887 published
- 2026-05-11: disclosed: CVE-2026-44999 published
- 2026-05-18: patched: Duplicate advisory GHSA-m5j2-r859-r5cv withdrawn in favor of original