Critical · CVSS 9.6 May 15, 2026 · Updated May 19, 2026 · Cyera Research · Dark Reading

Claw Chain

Four Chainable Vulnerabilities in OpenClaw AI-Agent Servers

A defensive guide for security teams. Understand the attack chain, assess your exposure, and implement the 24-hour response checklist. These four vulnerabilities are individually dangerous — chained together, they enable full compromise of an AI-agent runtime.

~245K Exposed Servers
~65K Shodan Visible
4 CVEs Disclosed
9.6 Highest CVSS

Vulnerabilities

CVE-2026-44112 Critical · 9.6 Persistence

TOCTOU Filesystem Write Escape

A time-of-check/time-of-use race condition in the OpenShell sandbox allows an attacker to redirect file writes outside the permitted sandbox boundary. The validation check and the actual write operation target different paths, enabling the attacker to swap the target between the two operations.

Impact: Configuration tampering, backdoor placement, and persistent control over the agent runtime.
CVE-2026-44115 High · 8.8 Exfiltration

Execution Allowlist Env-Var Disclosure

Environment variables including API keys, tokens, and credentials leak through command execution behavior that appears safe during the allowlist validation phase. The disclosure occurs after the check passes, exposing secrets through side-channel execution output.

Impact: Exposure of API keys, bearer tokens, cloud credentials, and authentication material.
CVE-2026-44118 High · 7.8 Privilege Escalation

MCP Loopback Privilege Escalation

A local process with a valid bearer token can elevate to owner-level privileges by abusing a client-controlled ownership flag in the MCP loopback interface. The server trusts the client's self-reported privilege claim without server-side verification.

Impact: Owner-level control over gateway configuration, scheduling, execution management, and agent orchestration.
CVE-2026-44113 High · 7.7 Exfiltration

TOCTOU Filesystem Read Escape

Attackers can swap validated file paths with symbolic links pointing outside the allowed mount root between the path validation step and the actual read operation. This enables reading files the agent should not be able to access.

Impact: Exposure of sensitive host files, system credentials, configuration files, and internal source code outside the sandbox.

Attack Chain

1

Foothold

Attacker enters the OpenShell sandbox through a malicious plugin, prompt injection, or compromised external input.

Treat agent inputs and plugins as supply-chain artifacts. Review all agent-facing components with the same rigor applied to CI/CD scripts.

2

Exfiltration

Read escape and env-var disclosure vulnerabilities expose secrets, credentials, configuration files, and runtime artifacts.

Monitor agent reads, command output, and secret exposure paths. Assume any credential reachable by OpenClaw processes may already be compromised.

3

Privilege Escalation

MCP loopback flaw grants owner-level control over gateway configuration, scheduling, and execution management.

Validate identity and authorization server-side. Never trust client-controlled privilege flags without independent verification.

4

Persistence

Write escape modifies configuration, installs backdoors, or alters future agent behavior while appearing as routine automation.

Track configuration integrity and compare runtime behavior against known-good baselines. Alert on unexpected configuration changes.

Impact Areas

Agent Runtime

  • Environment variables
  • API keys and bearer tokens
  • Authentication material
  • Internal runtime artifacts

Host Filesystem

  • Files outside the sandbox
  • System credentials
  • Configuration files
  • Internal source code

Agent Privileges

  • Connected SaaS data
  • User prompts and outputs
  • Scheduling controls
  • Gateway and execution management

24-Hour Response Checklist

STEP 01 Confirm OpenClaw Exists in Your Environment Immediate

Search infrastructure records, container registries, endpoint inventories, cloud workloads, Kubernetes manifests, service catalogs, and developer environments for OpenClaw deployments. Include workstations and experimental cloud projects.

  • Hostname / service name — Identifies the asset and responsible team
  • Internet exposure — Determines urgency and external attack surface
  • OpenClaw version / patch date — Confirms whether April 23, 2026 fixes are present
  • Connected credentials — Determines secret-rotation scope
  • Connected SaaS systems — Determines possible blast radius
  • Agent plugins and skills — Identifies supply-chain inputs that may have created the initial foothold
STEP 02 Apply the April 23, 2026 Patches Immediate

Apply fixes covering GHSA-5h3g-6xhh-rg6p, GHSA-wppj-c6mr-83jj, GHSA-r6xh-pqhr-v4xh, and GHSA-x3h8-jrgh-p8jx. Treat patching as urgent even for internal instances — internal agent deployments often have broad access to sensitive systems.

STEP 03 Remove Public Exposure Immediate

Place OpenClaw behind authentication, firewall rules, VPN access, or service-to-service controls. An AI-agent control plane should not be exposed to the public internet. If it must be reachable, protect it with strong authentication, narrow allowlists, monitoring, and rate-limited access.

STEP 04 Rotate All Secrets Urgent

Assume that any environment variable or credential reachable by OpenClaw processes may already be compromised. Rotate API keys, tokens, bearer credentials, cloud credentials, database credentials, webhook tokens, OAuth secrets, and any credential used by connected plugins.

  • Priority 1: Cloud provider keys and deployment credentials
  • Priority 2: SaaS API tokens and OAuth client secrets
  • Priority 3: Source-code repository tokens
  • Priority 4: Webhook secrets and automation tokens
  • Priority 5: Low-privilege integration tokens
STEP 05 Audit Agent Access Like a Service Account Urgent

Each agent should have a named owner, a business purpose, scoped permissions, a credential lifecycle, logging, approval workflows, and removal procedures. Ask: What can it read? Write? Execute? What plugins can it install? What external data can influence its behavior?

STEP 06 Review Plugins, Prompts, and External Inputs Important

The initial foothold may come from a malicious plugin, prompt injection, or compromised external input. Review all agent-facing components with the same rigor applied to dependencies and CI/CD scripts. Do not assume natural-language instructions are safe merely because they are not executable code.

Agent Governance Framework

Named Ownership

Every agent deployment must have a named owner and a documented business purpose. Ownerless agents are unmanaged attack surfaces.

Scoped Permissions

Apply least privilege. Agents should not inherit every credential, repository, SSH key, or cloud token available to a developer session.

Credential Lifecycle

Use separate tokens for agent workflows with short expiration windows. Avoid exposing production credentials to local coding assistants.

Plugin Review

Treat agent plugins and skills as supply-chain artifacts. Require peer review and ownership tracking for all agent-facing components.

Behavioral Monitoring

Log agent reads, writes, command output, and API calls. Alert on configuration changes, unusual file access, and unexpected outbound traffic.

Endpoint Allowlisting

Maintain an allowlist of approved AI model endpoints. Alert when settings point to unknown domains or proxy services.

References

Advisory analysis by Spectreworks AI. Original research by Cyera Research. All defensive recommendations are based on publicly available disclosure information. Verify patch applicability against your specific deployment before production changes.