Claw Chain
Four Chainable Vulnerabilities in OpenClaw AI-Agent Servers
A defensive guide for security teams. Understand the attack chain, assess your exposure, and implement the 24-hour response checklist. These four vulnerabilities are individually dangerous — chained together, they enable full compromise of an AI-agent runtime.
Vulnerabilities
TOCTOU Filesystem Write Escape
A time-of-check/time-of-use race condition in the OpenShell sandbox allows an attacker to redirect file writes outside the permitted sandbox boundary. The validation check and the actual write operation target different paths, enabling the attacker to swap the target between the two operations.
Execution Allowlist Env-Var Disclosure
Environment variables including API keys, tokens, and credentials leak through command execution behavior that appears safe during the allowlist validation phase. The disclosure occurs after the check passes, exposing secrets through side-channel execution output.
MCP Loopback Privilege Escalation
A local process with a valid bearer token can elevate to owner-level privileges by abusing a client-controlled ownership flag in the MCP loopback interface. The server trusts the client's self-reported privilege claim without server-side verification.
TOCTOU Filesystem Read Escape
Attackers can swap validated file paths with symbolic links pointing outside the allowed mount root between the path validation step and the actual read operation. This enables reading files the agent should not be able to access.
Attack Chain
Foothold
Attacker enters the OpenShell sandbox through a malicious plugin, prompt injection, or compromised external input.
Treat agent inputs and plugins as supply-chain artifacts. Review all agent-facing components with the same rigor applied to CI/CD scripts.
Exfiltration
Read escape and env-var disclosure vulnerabilities expose secrets, credentials, configuration files, and runtime artifacts.
Monitor agent reads, command output, and secret exposure paths. Assume any credential reachable by OpenClaw processes may already be compromised.
Privilege Escalation
MCP loopback flaw grants owner-level control over gateway configuration, scheduling, and execution management.
Validate identity and authorization server-side. Never trust client-controlled privilege flags without independent verification.
Persistence
Write escape modifies configuration, installs backdoors, or alters future agent behavior while appearing as routine automation.
Track configuration integrity and compare runtime behavior against known-good baselines. Alert on unexpected configuration changes.
Impact Areas
Agent Runtime
- Environment variables
- API keys and bearer tokens
- Authentication material
- Internal runtime artifacts
Host Filesystem
- Files outside the sandbox
- System credentials
- Configuration files
- Internal source code
Agent Privileges
- Connected SaaS data
- User prompts and outputs
- Scheduling controls
- Gateway and execution management
24-Hour Response Checklist
Search infrastructure records, container registries, endpoint inventories, cloud workloads, Kubernetes manifests, service catalogs, and developer environments for OpenClaw deployments. Include workstations and experimental cloud projects.
- Hostname / service name — Identifies the asset and responsible team
- Internet exposure — Determines urgency and external attack surface
- OpenClaw version / patch date — Confirms whether April 23, 2026 fixes are present
- Connected credentials — Determines secret-rotation scope
- Connected SaaS systems — Determines possible blast radius
- Agent plugins and skills — Identifies supply-chain inputs that may have created the initial foothold
Apply fixes covering GHSA-5h3g-6xhh-rg6p, GHSA-wppj-c6mr-83jj, GHSA-r6xh-pqhr-v4xh, and GHSA-x3h8-jrgh-p8jx. Treat patching as urgent even for internal instances — internal agent deployments often have broad access to sensitive systems.
Place OpenClaw behind authentication, firewall rules, VPN access, or service-to-service controls. An AI-agent control plane should not be exposed to the public internet. If it must be reachable, protect it with strong authentication, narrow allowlists, monitoring, and rate-limited access.
Assume that any environment variable or credential reachable by OpenClaw processes may already be compromised. Rotate API keys, tokens, bearer credentials, cloud credentials, database credentials, webhook tokens, OAuth secrets, and any credential used by connected plugins.
- Priority 1: Cloud provider keys and deployment credentials
- Priority 2: SaaS API tokens and OAuth client secrets
- Priority 3: Source-code repository tokens
- Priority 4: Webhook secrets and automation tokens
- Priority 5: Low-privilege integration tokens
Each agent should have a named owner, a business purpose, scoped permissions, a credential lifecycle, logging, approval workflows, and removal procedures. Ask: What can it read? Write? Execute? What plugins can it install? What external data can influence its behavior?
The initial foothold may come from a malicious plugin, prompt injection, or compromised external input. Review all agent-facing components with the same rigor applied to dependencies and CI/CD scripts. Do not assume natural-language instructions are safe merely because they are not executable code.
Agent Governance Framework
Named Ownership
Every agent deployment must have a named owner and a documented business purpose. Ownerless agents are unmanaged attack surfaces.
Scoped Permissions
Apply least privilege. Agents should not inherit every credential, repository, SSH key, or cloud token available to a developer session.
Credential Lifecycle
Use separate tokens for agent workflows with short expiration windows. Avoid exposing production credentials to local coding assistants.
Plugin Review
Treat agent plugins and skills as supply-chain artifacts. Require peer review and ownership tracking for all agent-facing components.
Behavioral Monitoring
Log agent reads, writes, command output, and API calls. Alert on configuration changes, unusual file access, and unexpected outbound traffic.
Endpoint Allowlisting
Maintain an allowlist of approved AI model endpoints. Alert when settings point to unknown domains or proxy services.
References
- Cyera Research "Claw Chain: Cyera Research Unveil Four Chainable Vulnerabilities in OpenClaw" — May 15, 2026
- Dark Reading "'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments" — May 2026
-
CVE Program
CVE-2026-44112 (CVSS 9.6) — TOCTOU Filesystem Write Escape
CVE-2026-44115 (CVSS 8.8) — Execution Allowlist Env-Var Disclosure
CVE-2026-44118 (CVSS 7.8) — MCP Loopback Privilege Escalation
CVE-2026-44113 (CVSS 7.7) — TOCTOU Filesystem Read Escape - GitHub Security Advisories GHSA-5h3g-6xhh-rg6p · GHSA-wppj-c6mr-83jj · GHSA-r6xh-pqhr-v4xh · GHSA-x3h8-jrgh-p8jx