Executive brief
OpenClaw is an AI assistant platform that executes tasks locally. A flaw in how the system processes background task output allows lower-trust data to be mixed into trusted system events, enabling attackers to inject malicious prompts that influence subsequent AI agent decisions. This could lead to unauthorized actions or data exposure.
Technical details
The vulnerability is a trust boundary violation (CWE-501) where lower-trust background runtime output is incorrectly injected into trusted System: events. Additionally, local asynchronous execution completion fails to apply the intended exec-event downgrade, which should demote trust levels. An attacker with local access can craft malicious background output that gets promoted to trusted System events, allowing prompt injection in subsequent agent turns. The issue affects OpenClaw versions up to 2026.4.2 and is patched in version 2026.4.8.
Affected products
- OpenClaw openclaw <= 2026.4.2
Timeline
- 2026-04-09: disclosed
- 2026-04-08: patched: Fix available in version 2026.4.8; commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5