OpenClaw
- < 2026.4.29
A policy bypass vulnerability has been identified in OpenClaw versions prior to 2026.4.29. This vulnerability allows authenticated senders to circumvent DM-only and allowFrom policy checks in QQBot admin commands. As a result, attackers can route admin commands from unauthorized senders or contexts to perform restricted actions that should have been blocked by policy.
Exploitation of this vulnerability could enable unauthorized execution of QQBot admin commands, bypassing established policy checks and potentially leading to unauthorized actions within the application.
Users can update to OpenClaw version 2026.4.29 or later to address this vulnerability. Alternatively, exported QQBot admin commands can be disabled or access to QQBot can be restricted until the update is applied.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.