Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 16, 2026 (about 4 months ago).

distribution · May 16, 2026

Four OpenClaw flaws let attackers steal data, escalate privileges, and escape sandbox

Share the canonical public link.

Share as image

Four OpenClaw flaws in the Claw Chain enable attackers to steal data, escalate privileges, and escape the sandbox. The vulnerabilities were disclosed on May 15, 2026, and patched in OpenClaw version 2026.4.22. OpenClaw has more than 3.2 million users and enterprise adoption by Nvidia with NemoClaw and Tencent with ClawPro. A Koi Security audit of ClawHub found 341 malicious entries out of 2,857 available skills. Nvidia addressed some security concerns in March 2026 with NemoClaw built in partnership with Cisco, CrowdStrike, Google, and Microsoft Security.

Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)

Supporting evidence