🚨 CVE-2026-100572
OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket address. In deployments where OpenClaw sits behind a trusted reverse proxy or tunnel and multiple external clients share a single socket address, an unauthenticated sender can exhaust the shared invalid-token budget, causing subsequent legitimate Synology Chat webhook callbacks to be rejected until the rate-limit window expires. The attacker cannot obtain a valid token or read message data; the impact is temporary loss of channel availability. Fixed in 2026.8.1.
🎖@cveNotify
OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket address. In deployments where OpenClaw sits behind a trusted reverse proxy or tunnel and multiple external clients share a single socket address, an unauthenticated sender can exhaust the shared invalid-token budget, causing subsequent legitimate Synology Chat webhook callbacks to be rejected until the rate-limit window expires. The attacker cannot obtain a valid token or read message data; the impact is temporary loss of channel availability. Fixed in 2026.8.1.
🎖@cveNotify
GitHub
Synology pre-auth limits could lock out valid webhooks
### Summary
Synology pre-auth limits could lock out valid webhooks. In affected versions, invalid-token throttling ran before authentication and identified requests by the raw proxy socket address...
Synology pre-auth limits could lock out valid webhooks. In affected versions, invalid-token throttling ran before authentication and identified requests by the raw proxy socket address...
🚨 CVE-2026-100573
OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list and invoke denied tools to access data or perform actions the operator intended to exclude from the sandbox.
🎖@cveNotify
OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list and invoke denied tools to access data or perform actions the operator intended to exclude from the sandbox.
🎖@cveNotify
GitHub
MCP loopback could omit sandbox tool deny policy
### Summary
MCP loopback could omit sandbox tool deny policy. In affected versions, a sandboxed coding-agent session could list and invoke tools explicitly denied by `sandbox.tools.deny`.
This ad...
MCP loopback could omit sandbox tool deny policy. In affected versions, a sandboxed coding-agent session could list and invoke tools explicitly denied by `sandbox.tools.deny`.
This ad...
🚨 CVE-2026-100574
OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS recheck, a trusted hostname that resolves to an unspecified address (0.0.0.0 or ::) bypasses the SSRF destination validation. An attacker who can influence DNS for an allowed hostname can therefore cause a guarded fetch to reach a service bound only to loopback and disclose its response; the practical impact depends on the reachable service and the data it returns. Fixed in 2026.8.1.
🎖@cveNotify
OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS recheck, a trusted hostname that resolves to an unspecified address (0.0.0.0 or ::) bypasses the SSRF destination validation. An attacker who can influence DNS for an allowed hostname can therefore cause a guarded fetch to reach a service bound only to loopback and disclose its response; the practical impact depends on the reachable service and the data it returns. Fixed in 2026.8.1.
🎖@cveNotify
GitHub
Trusted-host DNS checks could admit unspecified addresses
### Summary
Trusted-host DNS checks could admit unspecified addresses. In affected versions, a trusted hostname that resolved to `0.0.0.0` or `::` could connect to a loopback service despite OpenC...
Trusted-host DNS checks could admit unspecified addresses. In affected versions, a trusted hostname that resolved to `0.0.0.0` or `::` could connect to a loopback service despite OpenC...
🚨 CVE-2026-100575
OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.
🎖@cveNotify
OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.
🎖@cveNotify
GitHub
Slack group DMs could skip sender allowlists
### Summary
Slack group DMs could skip sender allowlists. In affected versions, a sender in a multi-person direct message could trigger an OpenClaw agent even when the configured Slack group sende...
Slack group DMs could skip sender allowlists. In affected versions, a sender in a multi-person direct message could trigger an OpenClaw agent even when the configured Slack group sende...
🚨 CVE-2026-100576
OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows attackers to bypass SSRF protections by reaching blocked destinations. Attackers can use the wait --fn function against an existing browser session to request loopback or private destinations without navigation checks applied to other browser actions.
🎖@cveNotify
OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows attackers to bypass SSRF protections by reaching blocked destinations. Attackers can use the wait --fn function against an existing browser session to request loopback or private destinations without navigation checks applied to other browser actions.
🎖@cveNotify
GitHub
Browser wait predicates could reach blocked destinations
### Summary
Browser wait predicates could reach blocked destinations. In affected versions, `wait --fn` against an existing browser session could cause requests to loopback or private destinations...
Browser wait predicates could reach blocked destinations. In affected versions, `wait --fn` against an existing browser session could cause requests to loopback or private destinations...
🚨 CVE-2026-100577
OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised provider can return private or loopback URLs to cause the CLI to make requests to internal services accessible from the OpenClaw host.
🎖@cveNotify
OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised provider can return private or loopback URLs to cause the CLI to make requests to internal services accessible from the OpenClaw host.
🎖@cveNotify
GitHub
Video asset downloads could reach private destinations
### Summary
Video asset downloads could reach private destinations. In affected versions, the OpenClaw CLI fetched a provider-returned video asset URL without applying the network destination chec...
Video asset downloads could reach private destinations. In affected versions, the OpenClaw CLI fetched a provider-returned video asset URL without applying the network destination chec...
🚨 CVE-2026-100578
OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, a write-scoped non-owner caller can start a chat turn whose tool inventory includes the `gateway` and `cron` tools, causing the agent to invoke owner-only configuration or scheduling operations, including persistent state changes. Practical impact depends on the tools selected by the model and the caller's ability to steer the turn. Shared-secret token and password callers are treated as fully trusted operators under OpenClaw's security model and are outside the scope of this issue. The issue is fixed in 2026.7.1; as a workaround, restrict chat.send to administrators in identity-bearing deployments and remove `gateway` and `cron` from affected agent tool policies.
🎖@cveNotify
OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, a write-scoped non-owner caller can start a chat turn whose tool inventory includes the `gateway` and `cron` tools, causing the agent to invoke owner-only configuration or scheduling operations, including persistent state changes. Practical impact depends on the tools selected by the model and the caller's ability to steer the turn. Shared-secret token and password callers are treated as fully trusted operators under OpenClaw's security model and are outside the scope of this issue. The issue is fixed in 2026.7.1; as a workaround, restrict chat.send to administrators in identity-bearing deployments and remove `gateway` and `cron` from affected agent tool policies.
🎖@cveNotify
GitHub
chat.send could expose owner-only infrastructure tools
### Summary
`chat.send` could expose owner-only infrastructure tools. In affected versions, a non-owner caller in an identity-bearing Gateway deployment could start a chat turn whose tool inventor...
`chat.send` could expose owner-only infrastructure tools. In affected versions, a non-owner caller in an identity-bearing Gateway deployment could start a chat turn whose tool inventor...
🚨 CVE-2026-100579
OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator scopes), a write-scoped caller can supply another sender's identifier to the channel authorization checks and invoke a channel action under that spoofed requester identity, reaching operations the channel adapter would have denied to the real caller. Practical impact depends on the enabled channel, the action, and the target account's permissions. Shared-secret token and password callers are full trusted operators under OpenClaw's security model and are out of scope. The issue is fixed in 2026.7.1; as a workaround, restrict message.action to administrators and disable sensitive channel actions that rely on requester identity.
🎖@cveNotify
OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator scopes), a write-scoped caller can supply another sender's identifier to the channel authorization checks and invoke a channel action under that spoofed requester identity, reaching operations the channel adapter would have denied to the real caller. Practical impact depends on the enabled channel, the action, and the target account's permissions. Shared-secret token and password callers are full trusted operators under OpenClaw's security model and are out of scope. The issue is fixed in 2026.7.1; as a workaround, restrict message.action to administrators and disable sensitive channel actions that rely on requester identity.
🎖@cveNotify
GitHub
message.action could trust spoofed requester provenance
### Summary
`message.action` could trust spoofed requester provenance. In affected versions, a write-scoped caller in an identity-bearing Gateway deployment could supply another sender's ident...
`message.action` could trust spoofed requester provenance. In affected versions, a write-scoped caller in an identity-bearing Gateway deployment could supply another sender's ident...
🚨 CVE-2026-100580
OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to steer a tool-enabled agent can therefore create a persistent cron job that executes attacker-selected commands with the privileges of the OpenClaw process user, resulting in access to host files and credentials and impact to scheduled service availability. The issue is limited to cron jobs created or edited through the model-facing cron tool; direct CLI and authorized Gateway scheduling surfaces are trusted operator controls. Fixed in 2026.7.1.
🎖@cveNotify
OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to steer a tool-enabled agent can therefore create a persistent cron job that executes attacker-selected commands with the privileges of the OpenClaw process user, resulting in access to host files and credentials and impact to scheduled service availability. The issue is limited to cron jobs created or edited through the model-facing cron tool; direct CLI and authorized Gateway scheduling surfaces are trusted operator controls. Fixed in 2026.7.1.
🎖@cveNotify
GitHub
Cron tool could accept mixed-case command payloads
### Summary
Cron tool could accept mixed-case command payloads. In affected versions, a mixed-case payload kind could pass the agent-facing shell-execution guard and later normalize into a command...
Cron tool could accept mixed-case command payloads. In affected versions, a mixed-case payload kind could pass the agent-facing shell-execution guard and later normalize into a command...
🚨 CVE-2026-100581
OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device backups or extracted App Group containers can recover valid Gateway tokens and passwords to authenticate with operator authority.
🎖@cveNotify
OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device backups or extracted App Group containers can recover valid Gateway tokens and passwords to authenticate with operator authority.
🎖@cveNotify
GitHub
iOS Share Extension stored Gateway credentials outside Keychain
### Summary
The iOS Share Extension stored Gateway credentials outside Keychain. In affected versions, the app stored the Share relay token and password as cleartext JSON in App Group UserDefaults...
The iOS Share Extension stored Gateway credentials outside Keychain. In affected versions, the app stored the Share relay token and password as cleartext JSON in App Group UserDefaults...
🚨 CVE-2026-100582
OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a steered agent with access to a channel read action can therefore retrieve content or metadata from channels or rooms excluded by the operator's read policy; the practical impact depends on the permissions held by the connected bot account. The issue is fixed in 2026.8.1.
🎖@cveNotify
OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a steered agent with access to a channel read action can therefore retrieve content or metadata from channels or rooms excluded by the operator's read policy; the practical impact depends on the permissions held by the connected bot account. The issue is fixed in 2026.8.1.
🎖@cveNotify
GitHub
Channel read actions could skip target allowlists
### Summary
Channel read actions could skip target allowlists. In affected versions, explicit read targets in Microsoft Teams, Feishu, Matrix, and Google Chat could reach channels or rooms outside...
Channel read actions could skip target allowlists. In affected versions, explicit read targets in Microsoft Teams, Feishu, Matrix, and Google Chat could reach channels or rooms outside...
🚨 CVE-2026-100583
OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists. Attackers can bypass the configured Discord read-target policy to access guild metadata from servers or channels outside the operator's allowlist.
🎖@cveNotify
OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists. Attackers can bypass the configured Discord read-target policy to access guild metadata from servers or channels outside the operator's allowlist.
🎖@cveNotify
GitHub
Discord guild reads could skip target allowlists
### Summary
Discord guild reads could skip target allowlists. In affected versions, guild metadata actions could read information from a server or channel outside the configured Discord read-targe...
Discord guild reads could skip target allowlists. In affected versions, guild metadata actions could read information from a server or channel outside the configured Discord read-targe...
🚨 CVE-2026-100584
OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could approve an exact executable resolved from PATH but subsequently execute a same-named executable located in the workspace directory. If lower-trust content can place an executable with an approved basename into an agent-writable workspace and steer an approved PowerShell command that uses a bare executable name, OpenClaw may run the workspace file instead of the allowlisted path, executing arbitrary code with the privileges of the Gateway or node-host user. The issue does not require replacement of the approved executable itself. Version 2026.7.1 contains a fix; as a workaround, avoid bare executable names in approved PowerShell commands and keep executable files out of agent-writable workspaces.
🎖@cveNotify
OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could approve an exact executable resolved from PATH but subsequently execute a same-named executable located in the workspace directory. If lower-trust content can place an executable with an approved basename into an agent-writable workspace and steer an approved PowerShell command that uses a bare executable name, OpenClaw may run the workspace file instead of the allowlisted path, executing arbitrary code with the privileges of the Gateway or node-host user. The issue does not require replacement of the approved executable itself. Version 2026.7.1 contains a fix; as a workaround, avoid bare executable names in approved PowerShell commands and keep executable files out of agent-writable workspaces.
🎖@cveNotify
GitHub
Windows allowlist execution could use workspace shadows
### Summary
Windows allowlist execution could use workspace shadows. In affected versions, PowerShell command analysis could approve an exact executable from `PATH` but later run a same-named exec...
Windows allowlist execution could use workspace shadows. In affected versions, PowerShell command analysis could approve an exact executable from `PATH` but later run a same-named exec...
🚨 CVE-2026-100585
OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command access can approve or deny a pending permission request intended for the owner, causing the requested action to proceed without owner consent. The practical impact depends on the pending action and the host capabilities requested by the Claude Code run. The issue is fixed in version 2026.7.1.
🎖@cveNotify
OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command access can approve or deny a pending permission request intended for the owner, causing the requested action to proceed without owner consent. The practical impact depends on the pending action and the host capabilities requested by the Claude Code run. The issue is fixed in version 2026.7.1.
🎖@cveNotify
GitHub
Claude permission replies could omit owner authorization
### Summary
Claude permission replies could omit owner authorization. In affected versions, an authorized non-owner channel sender could approve or deny a pending Claude Code permission request th...
Claude permission replies could omit owner authorization. In affected versions, an authorized non-owner channel sender could approve or deny a pending Claude Code permission request th...
🚨 CVE-2026-100586
OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.
🎖@cveNotify
OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.
🎖@cveNotify
GitHub
Codex bind could omit owner authorization
### Summary
Codex bind could omit owner authorization. In affected versions, an authorized non-owner channel sender could create a native Codex conversation binding and start host-capable Codex tu...
Codex bind could omit owner authorization. In affected versions, an authorized non-owner channel sender could create a native Codex conversation binding and start host-capable Codex tu...
🚨 CVE-2026-100587
OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute MCP processes with OpenClaw user privileges, affecting host confidentiality, integrity, and availability.
🎖@cveNotify
OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute MCP processes with OpenClaw user privileges, affecting host confidentiality, integrity, and availability.
🎖@cveNotify
GitHub
Codex computer-use install could omit owner authorization
### Summary
Codex computer-use install could omit owner authorization. In affected versions, an authorized non-owner channel sender could install a Codex plugin and cause its configured MCP proces...
Codex computer-use install could omit owner authorization. In affected versions, an authorized non-owner channel sender could install a Codex plugin and cause its configured MCP proces...
🚨 CVE-2026-100589
OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations, inspecting or manipulating the connected browser profile and its authenticated state.
🎖@cveNotify
OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations, inspecting or manipulating the connected browser profile and its authenticated state.
🎖@cveNotify
GitHub
Browser node targets could bypass sandbox host control
### Summary
Browser node targets could bypass sandbox host control. In affected versions, a sandboxed browser tool could select a paired node and reach host browser actions despite `allowHostContr...
Browser node targets could bypass sandbox host control. In affected versions, a sandboxed browser tool could select a paired node and reach host browser actions despite `allowHostContr...
🚨 CVE-2026-100590
OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration. Attackers with command access can change the voice used by Talk responses for the configured provider, affecting configuration integrity without exposing credentials or granting additional host capabilities.
🎖@cveNotify
OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration. Attackers with command access can change the voice used by Talk responses for the configured provider, affecting configuration integrity without exposing credentials or granting additional host capabilities.
🎖@cveNotify
GitHub
Talk Voice changes could omit admin authorization
### Summary
Talk Voice changes could omit admin authorization. In affected versions, an authorized non-owner external-channel sender could use `/voice set` to persist the Gateway's configured ...
Talk Voice changes could omit admin authorization. In affected versions, an authorized non-owner external-channel sender could use `/voice set` to persist the Gateway's configured ...
🚨 CVE-2026-100591
OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-channel sender could therefore persistently enable or disable Active Memory for the Gateway, disabling memory recall for future sessions or re-enabling global recall where the owner expected it to remain disabled. The issue is limited to persistent global on/off mutations; session-level controls and read-only status remain governed by existing command policy. The issue is fixed in version 2026.7.1. (Suggested title: "OpenClaw before 2026.7.1 missing owner authorization check on Active Memory global toggles".)
🎖@cveNotify
OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-channel sender could therefore persistently enable or disable Active Memory for the Gateway, disabling memory recall for future sessions or re-enabling global recall where the owner expected it to remain disabled. The issue is limited to persistent global on/off mutations; session-level controls and read-only status remain governed by existing command policy. The issue is fixed in version 2026.7.1. (Suggested title: "OpenClaw before 2026.7.1 missing owner authorization check on Active Memory global toggles".)
🎖@cveNotify
GitHub
Active Memory global toggles could omit owner checks
### Summary
Active Memory global toggles could omit owner checks. In affected versions, an authorized non-owner external-channel sender could enable or disable Active Memory for the Gateway.
This...
Active Memory global toggles could omit owner checks. In affected versions, an authorized non-owner external-channel sender could enable or disable Active Memory for the Gateway.
This...
🚨 CVE-2026-100592
OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized but non-owner external-channel sender can issue the persistent '/dreaming on' and '/dreaming off' commands to enable or disable the Gateway's Memory Core dreaming behavior, disabling background memory processing or re-enabling durable memory promotion where the owner expected it to remain disabled; the practical confidentiality, integrity, and availability impact depends on stored conversation material and subsequent memory use. Read-only status and help commands remain governed by normal command policy. The issue is fixed in version 2026.7.1. As a workaround, disable dreaming commands in external channels or restrict channel command access to owners.
🎖@cveNotify
OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized but non-owner external-channel sender can issue the persistent '/dreaming on' and '/dreaming off' commands to enable or disable the Gateway's Memory Core dreaming behavior, disabling background memory processing or re-enabling durable memory promotion where the owner expected it to remain disabled; the practical confidentiality, integrity, and availability impact depends on stored conversation material and subsequent memory use. Read-only status and help commands remain governed by normal command policy. The issue is fixed in version 2026.7.1. As a workaround, disable dreaming commands in external channels or restrict channel command access to owners.
🎖@cveNotify
GitHub
Memory dreaming changes could omit owner checks
### Summary
Memory dreaming changes could omit owner checks. In affected versions, an authorized non-owner external-channel sender could enable or disable the Gateway's persistent Memory Core ...
Memory dreaming changes could omit owner checks. In affected versions, an authorized non-owner external-channel sender could enable or disable the Gateway's persistent Memory Core ...
🚨 CVE-2026-100593
OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An authorized non-owner channel sender can change whether the agent requires mention-based activation, causing the agent to respond more broadly in the group (exposing its responses to additional group traffic) or suppressing expected activation behavior until an owner restores the intended setting. The issue is fixed in version 2026.7.1.
🎖@cveNotify
OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An authorized non-owner channel sender can change whether the agent requires mention-based activation, causing the agent to respond more broadly in the group (exposing its responses to additional group traffic) or suppressing expected activation behavior until an owner restores the intended setting. The issue is fixed in version 2026.7.1.
🎖@cveNotify
GitHub
Group activation changes could omit owner authorization
### Summary
Group activation changes could omit owner authorization. In affected versions, an authorized non-owner channel sender could change whether a group required mention-based activation.
T...
Group activation changes could omit owner authorization. In affected versions, an authorized non-owner channel sender could change whether a group required mention-based activation.
T...