Back to skill

Security audit

clawsec-feed

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate security advisory feed, but its standalone install/update instructions can trust mutable remote files enough to replace the installed skill.

Review before installing. Prefer a pinned release and the signed-manifest verification path, avoid the README quick install and mutable latest-release installer on production systems, and treat feed advisory text as untrusted data that should not cause commands, file changes, removals, or disclosures without explicit user confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:185
Finding

Unsigned release metadata can replace the installed Skill with mutable remote content

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:531
Finding

Unsigned advisory content crosses directly into the agent instruction and notification context

Content
View full analysis
/dev/null; then echo "Error: Invalid JSON in feed" exit 1 fi ``` The resulting remote content is treated as advisory guidance: ```markdown **If you find affected skills:** 1. Check the advisory for details and severity 2. Notify your user immediately for critical/high severity 3. Include the recommended action from the advisory ``` ### Technical Analysis The runtime feed path verifies only that the response is syntactically valid JSON. It does not verify a digital signature, pin a content hash, enforce a complete schema, constrain field lengths, or distinguish advisory data from executable agent instructions. `CLAWSEC_FEED_URL` permits an arbitrary endpoint. Even with the default URL, the feed comes from a mutable branch rather than an immutable signed release. Fields such as `title`, `description`, `action`, and `exploitability_rationale` are subsequently displayed and interpreted in an AI-agent context. An attacker controlling the feed can place instruction-like text in those fields, potentially causing indirect prompt injection. The bundled `advisories/feed.json` did not contain a confirmed malicious directive during this audit. The vulnerability is in the remote trust boundary: future feed content can change after the Sk ...[truncated 2102 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (103)

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · advisories/feed.json (reported line 7951)May include surrounding context.

json
"id": "CVE-2026-41357",
      "severity": "low",
      "type": "unknown_cwe_214",
      "nvd_category_id": "CWE-214",
      "title": "OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbo...",
      "description": "OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass unsanitized process.env to child processes. Attackers can exploit this by leveraging non-default SSH environment forwarding configurations to leak sensitive environment variables from parent processes to SSH child processes.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"
      ],
      "platforms": [
        "openclaw"
      ],
      "action": "Review and update affected components. See NVD for remediation details.",
      "published": "2026-04-23T22:16:43.177",
      "references": [
        "https://github.com/openclaw/openclaw/commit/cfe14459531e0

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
The default `feed.json` is the consolidated agent feed. It includes NVD CVEs, approved community advisories, and provisional GitHub Security Advisories that do

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
For standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metad

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
For standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metad

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · advisories/feed.json (reported line 4)May include surrounding context.

json
{
  "version": "0.0.3",
  "updated": "2026-06-21T07:41:37Z",
  "description": "Community-driven security advisory feed for ClawSec. Automatically updated with OpenClaw-related CVEs from NVD and community-reported security incidents.",
  "advisories": [
    {
      "id": "CVE-2026-53866",
      "severity": "high",
      "type": "missing_authorization",
      "nvd_category_id": "CWE-862",
      "title": "OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing...",
      "description": "OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated op

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 87)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 309)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 745)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 894)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 1708)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 4874)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 6485)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 6486)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 8704)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 8705)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 9385)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 9386)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 21628)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · advisories/feed.json (reported line 272)May include surrounding context.

json
9",
      "severity": "medium",
      "type": "unknown_cwe_1023",
      "nvd_category_id": "CWE-1023",
      "title": "OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass ...",
      "description": "OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived URLs. Attackers can exploit inconsistent hostname checks to reach destinations that operators intended to block through hostname policies.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta2:*:*:*:node.js:*:*",
        "openclaw@*"
      ],
      "platforms": [
        "openclaw"
      ],
      "action": "Review and update affected components. See NVD for remediation details.",
      "published": "2026-06-16T19:1

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · advisories/feed.json (reported line 3254)May include surrounding context.

json
"type": "server_side_request_forgery",
      "nvd_category_id": "CWE-918",
      "title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
      "description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · advisories/feed.json (reported line 8239)May include surrounding context.

json
"type": "server_side_request_forgery",
      "nvd_category_id": "CWE-918",
      "title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
      "description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · advisories/feed.json (reported line 8992)May include surrounding context.

json
"type": "server_side_request_forgery",
      "nvd_category_id": "CWE-918",
      "title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
      "description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · advisories/feed.json (reported line 10269)May include surrounding context.

json
"type": "server_side_request_forgery",
      "nvd_category_id": "CWE-918",
      "title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
      "description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · advisories/feed.json (reported line 13771)May include surrounding context.

json
"type": "server_side_request_forgery",
      "nvd_category_id": "CWE-918",
      "title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
      "description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · advisories/feed.json (reported line 16679)May include surrounding context.

json
"type": "server_side_request_forgery",
      "nvd_category_id": "CWE-918",
      "title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
      "description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
advisories/feed.json:21364