Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 17, 2026 (about 4 months ago).

people · May 17, 2026

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

Share the canonical public link.

Share as image

Security researchers disclosed four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The flaws in Claw Chain affect OpenClaw 2026.4.22 and were discovered by Vladimir Tokarev. Following responsible disclosure, all four vulnerabilities have been addressed in OpenClaw version 2026.4.22. OpenClaw has more than 3.2 million users and is integrated with ChatGPT subscriptions through OpenAI. A prior remote code execution vulnerability CVE-2026-25253 was reported in January 2026.

Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)

Supporting evidence