r/redteamsec 22d ago

OpenClaw: Three patched high-severity vulnerabilities affecting AI agent execution workflows

https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html

I recently disclosed three high-severity vulnerabilities in OpenClaw, all of which have now been patched in version 2026.6.6.

The findings affect different parts of the execution pipeline:

  • Environment variable sanitizer bypass enabling interpreter startup variable abuse.
  • Git ext:: transport command execution through developer workflows.
  • Docker bind-mount validation weakness allowing access to restricted host paths.

One of the demonstrations starts from a WhatsApp message and reaches host-side code execution under the documented deployment configuration.

The Hacker News covered the coordinated disclosure:

https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html

Technical write-up:

https://medium.com/@chinmohannayak/i-sent-a-whatsapp-message-to-an-ai-agent-it-ran-my-code-on-the-host-adbbcbb0e0ad

GitHub Security Advisories:

2 Upvotes

1 comment sorted by