OpenClaw
- < 2026.6.6
A network policy bypass vulnerability has been identified in OpenClaw versions prior to 2026.6.6. This vulnerability resides in the sandbox exec-server, where lower-trust callers can send HTTP requests that bypass OpenClaw's network restrictions. As a result, these requests can access internal network resources that should have been blocked by the application's policy.
Exploitation of this vulnerability allows lower-trust callers to access internal network destinations that should have been restricted, potentially leading to unauthorized access to network resources.
Users are advised to upgrade to OpenClaw version 2026.6.6 or later. Before upgrading, it is recommended to restrict the affected feature to trusted operators or disable it if not needed. As a general practice, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when it is not needed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.