OpenClaw’s official GitHub security-advisories page lists multiple vulnerabilities published on 30 June 2026. Several are marked high severity and concern who can invoke tools, install plugins, mutate messages or reach owner-only functionality.
OpenClaw Watch analysis
What happened
The advisories cover a broad slice of OpenClaw’s control plane: model overrides that could miss administrator authorisation, Feishu and Discord permission checks, remote symlink handling, durable exec approvals, plugin-install policy and MCP loopback access.
The index also lists a moderate issue involving plugin-install commands, alongside a high-severity issue that could allow non-owner persistence. The page identifies the advisories and their severity, but this evidence does not establish affected versions, patch status or exploitability in the wild.
Key findings
- Authorisation gaps
Several entries concern requests that could bypass or skip checks tied to administrators, owners or requesters. - Plugin risk
Two advisories concern installation controls, including a high-severity persistence issue. - Tool exposure
An MCP loopback issue is listed as potentially exposing owner-only tools to non-owner runs. - Messaging and community actions
Message mutations and Discord guild actions appear among the listed vulnerabilities. - Filesystem and execution boundaries
The index flags remote symlink-parent handling and durable exec-approval binding.
Why it matters
OpenClaw is an automation project whose usefulness depends on tools doing precisely what the right person asked. A cluster of advisories around authorisation and persistence is therefore more consequential than a routine bug parade: the boundary between “helpful agent” and “uninvited operator” is the whole plot.
The practical next step is version-specific checking. The supplied advisory index does not say which releases are affected or fixed, so operators should consult each advisory before assuming an upgrade, configuration change or mitigation is sufficient.
Our read
This merits attention from anyone running OpenClaw with plugins, messaging integrations or owner-only tools. Treat the advisory index as a triage list, then follow the individual records for affected versions and fixes.
What to watch
- Individual advisory pages identifying affected and fixed releases.
- Release notes or patches addressing the authorisation findings.
- Any maintainer guidance for plugin, MCP, Feishu or Discord configurations.
- Evidence of exploitation, withdrawals or corrections to the advisory records.
Discussion spark: If you run OpenClaw, which boundary would you audit first: plugins, messaging permissions, MCP tools or command execution?
Sources and evidence
- Security Advisories · openclaw/openclaw · GitHub (3 September 2026, 03:45 UTC)
OpenClaw Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by the OpenClaw Foundation.