3 Security Vulnerabilities Discovered in OpenClaw
·2026.04.21 23:35
Key point
Three security vulnerabilities were discovered in OpenClaw, including a sandbox bypass with a severity of 9.9.
Details
Three new security vulnerabilities (CVEs) have recently been announced in OpenClaw.
Details of the announced vulnerabilities are as follows:
- CVE-2026-41329: Sandbox bypass via heartbeat context, severity 9.9 (Critical)
- CVE-2026-41294: Environment variable injection (via .env file), severity 8.6
- CVE-2026-41303: Discord authentication bypass (Exec approvals), severity 8.8
These vulnerabilities were all fixed in versions between 2026.3.28 and 2026.3.31. Users running versions between January and March 2026 are advised to update to the latest version immediately to apply the patch.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.