people · May 17, 2026
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
Share the canonical public link.
Security researchers disclosed four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The flaws in Claw Chain affect OpenClaw 2026.4.22 and were discovered by Vladimir Tokarev. Following responsible disclosure, all four vulnerabilities have been addressed in OpenClaw version 2026.4.22. OpenClaw has more than 3.2 million users and is integrated with ChatGPT subscriptions through OpenAI. A prior remote code execution vulnerability CVE-2026-25253 was reported in January 2026.