PT-2026-26018 · Openclaw · Openclaw
Tdjackey
·
Published
2026-02-21
·
Updated
2026-03-18
·
CVE-2026-27524
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.21
Description
OpenClaw versions prior to 2026.2.21 are susceptible to prototype pollution attacks due to accepting prototype-reserved keys in runtime
/debug set override object values. Authorized /debug set callers can inject keys such as proto, constructor, or prototype to manipulate object prototypes and bypass command gate restrictions. The /debug functionality is disabled by default, and exploitation requires prior authorization. This issue affects runtime in-memory overrides only, which are not persistent and are cleared upon restart or reset. The API endpoint involved is /debug set. Vulnerable parameters include the override object values. Command gates like bash, config, and debug previously relied on inherited prototype values, which has been addressed by requiring own-property boolean flags.Recommendations
Update OpenClaw to version 2026.2.21 or later.
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw