Executive brief
OpenClaw is a local AI assistant that categorizes incoming messages and requests by trust level—distinguishing between "trusted" system prompts and "untrusted" user input. A flaw allows authenticated users to bypass this separation by sending specially-crafted wake hook requests that are incorrectly treated as trusted system commands instead of untrusted events. This could allow an authenticated attacker to manipulate the assistant's behavior or inject malicious instructions.
Technical details
The vulnerability is a trust boundary violation (CWE-501) in the `/hooks/wake` endpoint and associated mapped wake payload handling. Authenticated requests sent to this endpoint are incorrectly promoted into the `System:` prompt channel—the trusted instruction layer—instead of being processed as untrusted user events. The root cause involves mixing authenticated (but user-controlled) wake hook data with the trusted system prompt structure. An attacker with valid authentication credentials can exploit this by sending malicious wake payloads that will be interpreted with system-level privileges. The fix was released in version 2026.4.8 and verified against commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5.
Affected products
- OpenClaw OpenClaw <= 2026.4.2
Timeline
- 2026-04-09: disclosed
- 2026-04-08: patched: Fix available in version 2026.4.8