OpenClaw Improper Trust Labeling Vulnerability in Webhook-Triggered Cron Events

Vulnerability

A trust-labeling vulnerability has been identified in OpenClaw versions prior to 2026.4.20. The issue arises because the application fails to properly maintain untrusted labels for isolated cron awareness events. As a result, output from webhook-triggered cron agents can be incorrectly recorded as trusted system events. This vulnerability allows attackers to enhance the impact of prompt-injection attacks by misrepresenting untrusted events as reliable system events.

Impact

Exploitation of this vulnerability can lead to a misrepresentation of event trustworthiness, allowing untrusted cron events to be perceived as trusted system events. This distortion can amplify the effects of prompt-injection attacks, although it does not directly interfere with gateway authentication, tool policies, or sandboxing.

Reproduction

To reproduce this vulnerability, trigger a webhook that activates an isolated cron awareness event. The event will be recorded as a trusted system event, despite its untrusted origin. This can be verified by checking the event's trust label in the main session awareness stream, where it should appear as a trusted event.

Remediation

Users can update to OpenClaw version 2026.4.20 or later, where this vulnerability has been fixed.

Added: May 11, 2026, 7:05 PM
Updated: May 11, 2026, 7:05 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
0.0
relevance
8.0
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.