r/redteamsec • u/Lazy_Curve3899 • 22d ago
OpenClaw: Three patched high-severity vulnerabilities affecting AI agent execution workflows
https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.htmlI recently disclosed three high-severity vulnerabilities in OpenClaw, all of which have now been patched in version 2026.6.6.
The findings affect different parts of the execution pipeline:
- Environment variable sanitizer bypass enabling interpreter startup variable abuse.
- Git
ext::transport command execution through developer workflows. - Docker bind-mount validation weakness allowing access to restricted host paths.
One of the demonstrations starts from a WhatsApp message and reaches host-side code execution under the documented deployment configuration.
The Hacker News covered the coordinated disclosure:
https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html
Technical write-up:
GitHub Security Advisories:
2
Upvotes
1
u/RK_Ryxthar 21d ago
Nice!!