OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context.
The vulnerability results from the lack of integrity verification (CWE-345) of external hook metadata before placing it in the system event queue. An attacker provides crafted hook names, which the system incorrectly treats as trusted internal events. As a result, untrusted input data is escalated to a higher trust context of the agent, bypassing permission control mechanisms.
An attacker can cause privilege escalation by performing operations in the context of a trusted system agent, enabling unauthorized reading and modification of data protected by a higher level of trust.
OpenClaw should be updated to version 2026.4.10 or newer. The patch is available in the project repository (commit e3a845bde5b54f4f1e742d0a51ba9860f9619b29) and described in the official security advisory GHSA-7g8c-cfr3-vqqr.
OpenClaw in versions prior to 2026.4.10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XOpenclaw
APPOpenclaw< 2026.4.10
Related vulnerabilities
OpenClaw: ominięcie uwierzytelniania przez nieodświeżane tokeny bearer po rotacji SecretRef
OpenClaw: privilege escalation przez pominięcie zdarzeń async exec w heartbeat
OpenClaw: Authentication Bypass w trasie pomocniczej sandbox noVNC
OpenClaw: ekspozycja Chrome DevTools Protocol poza sandbox
OpenClaw — Auth Bypass w walidacji Feishu webhook umożliwia RCE