OpenClaw 2026.3.28 patches 8 security vulnerabilities including critical privilege escalation

✍️ OpenClawRadar📅 Published: April 1, 2026🔗 Source
OpenClaw 2026.3.28 patches 8 security vulnerabilities including critical privilege escalation
Ad

Critical security patches for OpenClaw

OpenClaw 2026.3.28 includes patches for 8 security vulnerabilities identified during a 3-day audit by Ant AI Security Lab. The audit found 33 issues total, with these 8 confirmed and fixed in the latest stable release.

Key vulnerabilities patched

The most significant issues include:

  • Critical severity privilege escalation: Lower-privileged operators could approve admin access via the /pair approve path
  • High severity sandbox escape: The message tool could be tricked into reading arbitrary local files using alias parameters
  • High severity node pairing approval bypass
  • High severity WebSocket session hijacking

Affected systems

These vulnerabilities affect multi-node OpenClaw setups and users of built-in tools like message or fal.

Ad

Security advisories

Detailed information is available in GitHub security advisories:

Update to OpenClaw 2026.3.28 immediately if you haven't already.

📖 Read the full source: r/openclaw

Ad

👀 See Also