OpenClaw Network Policy Bypass Vulnerability in Exec-Server

Vulnerability

A network policy bypass vulnerability has been identified in OpenClaw versions prior to 2026.6.6. This vulnerability resides in the sandbox exec-server, where lower-trust callers can send HTTP requests that bypass OpenClaw's network restrictions. As a result, these requests can access internal network resources that should have been blocked by the application's policy.

Impact

Exploitation of this vulnerability allows lower-trust callers to access internal network destinations that should have been restricted, potentially leading to unauthorized access to network resources.

Remediation

Users are advised to upgrade to OpenClaw version 2026.6.6 or later. Before upgrading, it is recommended to restrict the affected feature to trusted operators or disable it if not needed. As a general practice, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when it is not needed.

Added: Jul 17, 2026, 3:37 AM
Updated: Jul 17, 2026, 3:37 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.4
exploitability
6.0
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.