Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Multiple OpenClaw MCP and gateway vulnerabilities patched (CVE-2026-44118, -44995, -45001)

Three disclosed vulnerabilities in OpenClaw allow loopback clients to spoof owner context via bearer token headers, arbitrary code execution through unvalidated environment variables passed to MCP stdio servers, and bypass of guards on agent-facing gateway config.patch/config.apply endpoints so a prompt-injected model can persist changes to protected operator settings. All were fixed in releases 2026.4.20 and 2026.4.22.

Disclosed 6 May 2026 · Record updated 13 September 2026

Impact

Attackers could bypass owner-gated operations, execute arbitrary code via dangerous startup variables (NODE_OPTIONS, LD_PRELOAD, BASH_ENV) in spawned MCP server processes, and persist unauthorized changes to operator-trusted settings such as sandbox policy, plugin enablement, gateway auth/TLS and MCP server configuration.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44118
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44995
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-45001