PT-2026-26009 · Openclaw · Openclaw

Sean Nejad

·

Published

2026-03-18

·

Updated

2026-03-18

·

CVE-2026-22178

CVSS v3.1
6.5
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the stripBotMention function, allowing regex injection and denial of service. Attackers can craft nested-quantifier patterns or metacharacters in mention metadata to trigger catastrophic backtracking, block message processing, or remove unintended content before model processing.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2026-22178

Affected Products

Openclaw