PT-2026-26018 · Openclaw · Openclaw

Tdjackey

·

Published

2026-02-21

·

Updated

2026-03-18

·

CVE-2026-27524

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.21
Description OpenClaw versions prior to 2026.2.21 are susceptible to prototype pollution attacks due to accepting prototype-reserved keys in runtime /debug set override object values. Authorized /debug set callers can inject keys such as proto, constructor, or prototype to manipulate object prototypes and bypass command gate restrictions. The /debug functionality is disabled by default, and exploitation requires prior authorization. This issue affects runtime in-memory overrides only, which are not persistent and are cleared upon restart or reset. The API endpoint involved is /debug set. Vulnerable parameters include the override object values. Command gates like bash, config, and debug previously relied on inherited prototype values, which has been addressed by requiring own-property boolean flags.
Recommendations Update OpenClaw to version 2026.2.21 or later.

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

BDU:2026-05247
CVE-2026-27524
GHSA-62F6-MRCJ-V8H5

Affected Products

Openclaw