Summary
OpenClaw accepted prototype-reserved keys in runtime /debug set override object values (__proto__, constructor, prototype).
Impact
/debug is disabled by default, and exploitation requires an already authorized /debug set caller. No unauthenticated vector was identified.
This issue affects runtime in-memory overrides only (non-persistent and cleared on restart/reset). Given the required prior authorization boundary, this is treated as defense-in-depth hardening for command flag evaluation.
Affected Packages / Versions
- Package:
openclaw (npm)
- Latest published vulnerable version confirmed:
2026.2.19-2
- Vulnerable range:
<= 2026.2.19-2
- Patched in planned next release:
2026.2.21
Technical Details
- Runtime override merges now block reserved prototype keys during deep merge.
- Runtime override writes now sanitize nested object values to remove reserved prototype keys before storing overrides.
- Restricted command gates (
bash, config, debug) now require own-property boolean flags, preventing inherited prototype values from enabling commands.
Fix Commit(s)
fbb79d4013000552d6a2c23b9613d8b3cb92f6b6
Release Process Note
patched_versions is pre-set to 2026.2.21 so after the npm release is live, this advisory can be published immediately.
OpenClaw thanks @tdjackey for reporting.
References
Summary
OpenClaw accepted prototype-reserved keys in runtime
/debug setoverride object values (__proto__,constructor,prototype).Impact
/debugis disabled by default, and exploitation requires an already authorized/debug setcaller. No unauthenticated vector was identified.This issue affects runtime in-memory overrides only (non-persistent and cleared on restart/reset). Given the required prior authorization boundary, this is treated as defense-in-depth hardening for command flag evaluation.
Affected Packages / Versions
openclaw(npm)2026.2.19-2<= 2026.2.19-22026.2.21Technical Details
bash,config,debug) now require own-property boolean flags, preventing inherited prototype values from enabling commands.Fix Commit(s)
fbb79d4013000552d6a2c23b9613d8b3cb92f6b6Release Process Note
patched_versionsis pre-set to2026.2.21so after the npm release is live, this advisory can be published immediately.OpenClaw thanks @tdjackey for reporting.
References