In April researchers set out a chain of four vulnerabilities in OpenClaw, later analysed in a Cloud Security Alliance research note. An attacker could begin with either a booby-trapped plugin or an injected prompt and, by linking the flaws in sequence, finish with complete compromise of the machine running the agent.
The most severe link was a race condition in the sandbox, scored 9.6 on the CVSS scale. The chain shows why self-hosted agents concentrate risk: memory, credentials and access to the host all sit with the gateway, so a single way in can unlock the lot.
Version 2026.4.22 fixes all four flaws, and OpenClaw has come through an external audit since then. Anyone who ran an earlier release should assume that the keys the agent could reach may have been exposed, and rotate them.
Who was affected
OpenClaw installs older than 2026.4.22
The lesson: Run the current OpenClaw release and install plugins and skills sparingly, only from sources you trust. Anyone who used a release older than 2026.4.22 should replace every key the agent could touch.