OpenClaw 2026.3.28 patches 8 security vulnerabilities including critical privilege escalation

✍️ OpenClawRadar📅 Published: April 1, 2026🔗 Source
OpenClaw 2026.3.28 patches 8 security vulnerabilities including critical privilege escalation
Ad

Critical security patches for OpenClaw

OpenClaw 2026.3.28 includes patches for 8 security vulnerabilities identified during a 3-day audit by Ant AI Security Lab. The audit found 33 issues total, with these 8 confirmed and fixed in the latest stable release.

Key vulnerabilities patched

The most significant issues include:

  • Critical severity privilege escalation: Lower-privileged operators could approve admin access via the /pair approve path
  • High severity sandbox escape: The message tool could be tricked into reading arbitrary local files using alias parameters
  • High severity node pairing approval bypass
  • High severity WebSocket session hijacking

Affected systems

These vulnerabilities affect multi-node OpenClaw setups and users of built-in tools like message or fal.

Ad

Security advisories

Detailed information is available in GitHub security advisories:

Update to OpenClaw 2026.3.28 immediately if you haven't already.

📖 Read the full source: r/openclaw

Ad

👀 See Also

Hidden Audio Signals Hijack Voice AI Systems with 79-96% Success Rate
Security

Hidden Audio Signals Hijack Voice AI Systems with 79-96% Success Rate

Research shows imperceptible audio clips can force LALMs to execute unauthorized commands like web searches, file downloads, and email exfiltration with 79-96% success across 13 models including Mistral and Microsoft services.

OpenClawRadar
NPM Compromise via Axios Backdoor: Impact on AI Coding Agents
Security

NPM Compromise via Axios Backdoor: Impact on AI Coding Agents

On March 31, 2026, a DPRK-linked threat actor compromised npm by publishing backdoored versions of Axios (1.14.1 and 0.30.4) during a 3-hour window. The malware injected a dependency that downloaded a platform-specific RAT, harvested credentials, and self-erased, with AI coding agents like Claude Code and Cursor being particularly vulnerable due to automated npm installs.

OpenClawRadar
OpenClaw Security Vulnerabilities: Critical Framework Flaws Patched in 2026.3.28
Security

OpenClaw Security Vulnerabilities: Critical Framework Flaws Patched in 2026.3.28

Ant AI Security Lab identified 33 vulnerabilities in OpenClaw's core framework, with 8 critical issues patched in the 2026.3.28 release. The vulnerabilities include sandbox bypass, privilege escalation, session persistence after token revocation, SSRF risks, and allowlist degradation.

OpenClawRadar
Open Source AI Tools Pose Security Risks Through 'Illusory Security Through Transparency'
Security

Open Source AI Tools Pose Security Risks Through 'Illusory Security Through Transparency'

A Reddit post warns about malware disguised as open-source AI agents and tools, where malicious code can be hidden in large codebases that users assume are safe because they're on GitHub. The post describes how 'vibe-coding' and autonomous AI agents condition users to run unknown programs without review.

OpenClawRadar