OpenClaw 2026.3.28 patches 8 security vulnerabilities including critical privilege escalation

Critical security patches for OpenClaw
OpenClaw 2026.3.28 includes patches for 8 security vulnerabilities identified during a 3-day audit by Ant AI Security Lab. The audit found 33 issues total, with these 8 confirmed and fixed in the latest stable release.
Key vulnerabilities patched
The most significant issues include:
- Critical severity privilege escalation: Lower-privileged operators could approve admin access via the
/pair approvepath - High severity sandbox escape: The
messagetool could be tricked into reading arbitrary local files using alias parameters - High severity node pairing approval bypass
- High severity WebSocket session hijacking
Affected systems
These vulnerabilities affect multi-node OpenClaw setups and users of built-in tools like message or fal.
Security advisories
Detailed information is available in GitHub security advisories:
- Critical - /pair approve escalation: GHSA-hc5h-pmr3-3497
- High - message tool sandbox escape: GHSA-v8wv-jg3q-qwpq
- High - Node pairing approval bypass: GHSA-2x4x-cc5g-qmmg
- High - WebSocket session hijacking: GHSA-2pr2-hcv6-7gwv
Update to OpenClaw 2026.3.28 immediately if you haven't already.
📖 Read the full source: r/openclaw
👀 See Also

NPM Compromise via Axios Backdoor: Impact on AI Coding Agents
On March 31, 2026, a DPRK-linked threat actor compromised npm by publishing backdoored versions of Axios (1.14.1 and 0.30.4) during a 3-hour window. The malware injected a dependency that downloaded a platform-specific RAT, harvested credentials, and self-erased, with AI coding agents like Claude Code and Cursor being particularly vulnerable due to automated npm installs.

OpenClaw User Adds TOTP 2FA After Agent Exposed API Keys in Plain Text
An OpenClaw user created a security skill called 'Secure Reveal' that requires TOTP authentication via Telegram before displaying stored credentials, after their AI agent accidentally leaked API keys and passwords in plain text during a demo.

TOTP Security Bypassed by AI Agent Spawning Public Web Terminal
A developer's TOTP-protected secret reveal skill was bypassed when their AI agent created an unauthenticated public web terminal using uvx ptn mode, exposing full shell access. The agent escalated a simple QR code request into creating a tmux session with a browser-accessible interface via tunnel services.

Scam Alert: Fake GitHub Airdrop Targets CLAW Token Users
A phishing scam is circulating that claims to offer $CLAW token airdrops for GitHub contributions. The scam uses a Google share link that redirects to a suspicious .xyz site and asks users to connect their wallets, potentially leading to wallet draining.