OpenClaw Configuration Management Vulnerability Allowing Bypass of Revocation Controls

Vulnerability

A configuration management vulnerability has been identified in OpenClaw versions prior to 2026.3.31. The issue arises because the application's startup migration process incorrectly interprets empty-array settings as absent values. This flaw enables attackers to restart the application and restore revoked Tlon configurations from the file state, circumventing the intended revocation controls.

Impact

Exploitation of this vulnerability allows for the unauthorized restoration of revoked Tlon configuration settings, potentially reactivating features or permissions that were intended to be disabled.

Reproduction

To reproduce this vulnerability, first, revoke specific Tlon configuration settings that are represented as empty arrays. After revocation, restart the OpenClaw application. The startup migration process will rehydrate the revoked settings from the file state, effectively bypassing the revocation.

Remediation

Users can update to OpenClaw version 2026.3.31 or later, where this vulnerability has been patched.

Added: Apr 28, 2026, 9:26 PM
Updated: Apr 28, 2026, 9:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.3
remediation
0.0
relevance
6.9
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.