---
title: "OpenClaw Claw Chain Vulnerabilities: Case File · AgentDots"
description: "How four chained OpenClaw flaws, led by a CVSS 9.6 sandbox race condition, ran from a plugin or prompt injection to host takeover, and the 2026.4.22 fix."
url: https://agentdots.org/incidents/openclaw-claw-chain/
lang: en
---

Incident log · Security flaw

# Claw Chain: four linked OpenClaw flaws end in takeover

Researchers set out four OpenClaw vulnerabilities that link into a chain, starting from a rogue plugin or an injected prompt and finishing with the attacker controlling the host.

April 23, 2026 CriticalOpenClaw

In April researchers set out a chain of four vulnerabilities in OpenClaw, later analysed in a Cloud Security Alliance research note. An attacker could begin with either a booby-trapped plugin or an injected prompt and, by linking the flaws in sequence, finish with complete compromise of the machine running the agent.

The most severe link was a race condition in the sandbox, scored 9.6 on the CVSS scale. The chain shows why self-hosted agents concentrate risk: memory, credentials and access to the host all sit with the gateway, so a single way in can unlock the lot.

Version 2026.4.22 fixes all four flaws, and OpenClaw has come through an external audit since then. Anyone who ran an earlier release should assume that the keys the agent could reach may have been exposed, and rotate them.

## Who was affected

OpenClaw installs older than 2026.4.22

The lesson: Run the current OpenClaw release and install plugins and skills sparingly, only from sources you trust. Anyone who used a release older than 2026.4.22 should replace every key the agent could touch.

**Sources**

- [Cloud Security Alliance](https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/05/CSA%5Fresearch%5Fnote%5Fopenclaw-claw-chain-cve%5F20260517-csa-styled.pdf)

[OpenClaw](https://agentdots.org/agents/openclaw/)

Safety

[Work through the 18-point checklist →](https://agentdots.org/safety/checklist/)

## Incident log

September 28, 2026
[GPT-6.1 Astra withdrawn after failing its own tests](https://agentdots.org/incidents/astra-launch-halted/)

September 28, 2026
[Muse tells a stranger where its seller lives](https://agentdots.org/incidents/muse-shared-home-address/)

September 25, 2026
[Research agents post 53 user images to public hosts](https://agentdots.org/incidents/research-agents-posted-images/)

September 25, 2026
[Flaw opened a possible route into Muse machines](https://agentdots.org/incidents/muse-vm-vulnerability/)

September 20, 2026
[Amazon closes its store to Meta's Muse](https://agentdots.org/incidents/amazon-blocks-muse/)
