distribution · May 16, 2026
Four OpenClaw flaws let attackers steal data, escalate privileges, and escape sandbox
Share the canonical public link.
Four OpenClaw flaws in the Claw Chain enable attackers to steal data, escalate privileges, and escape the sandbox. The vulnerabilities were disclosed on May 15, 2026, and patched in OpenClaw version 2026.4.22. OpenClaw has more than 3.2 million users and enterprise adoption by Nvidia with NemoClaw and Tencent with ClawPro. A Koi Security audit of ClawHub found 341 malicious entries out of 2,857 available skills. Nvidia addressed some security concerns in March 2026 with NemoClaw built in partnership with Cisco, CrowdStrike, Google, and Microsoft Security.