CVE-2026-27001Disclosure(openclaw / openclaw)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (workspace path) into the agent system prompt without sanitization. If an attacker can cause OpenClaw to run inside a directory whose name contains control/format characters (for example newlines or Unicode bidi/zero-width markers), those characters could break the prompt structure and inject attacker-controlled instructions. Starting in version 2026.2.15, the workspace path is sanitized before it is embedded into any LLM prompt output, stripping Unicode control/format characters and explicit line/paragraph separators. Workspace path resolution also applies the same sanitization as defense-in-depth.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-02-20); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-20: 3Mentions · 2026-02-25: 1Mentions · 2026-03-27: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-27: 102-2002-2503-27
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-203
Disclosure2General1
2026-02-251
Disclosure1
2026-03-271
Disclosure1
Full discourse5 posts
  • bigmacd@bigmacd16684
    Disclosure

    SSRF, prompt injection, & auth bypass, 200x higher rate than LangChain or Ollama in lifetimes. CVE-2026-27001 shows the root cause: the working directory path embedded as a plain string in... #CyberSecurity #Vulnerabilities

    Post summary

    The post announces CVE-2026-27001 as a vulnerability involving SSRF, prompt injection, and auth bypass, providing some technical details but no evidence of a PoC, exploit tooling, active exploitation, or patch information.

    1000032
    5 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27001 (CVSS:8.6, HIGH) is Analyzed. OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (worksp..https://nvd.nist.gov/vuln/detail/CVE-2026-27001 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-27001 with a high CVSS score and notes that OpenClaw versions before 2026.2.15 embed the current working directory, but it does not provide details on exploitation or mitigation.

    0010073
    172 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-27001 📊 Severity: 8.6 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-27001 #CVE-2026-27001 #CVE #High #CyberSecurity #InfoSec https://t.co/iLwddmHyci

    Post summary

    New CVE-2026-27001 announced with a severity of 8.6 and high risk, affecting multiple unspecified products.

    0000038
    56 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27001 OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (workspace path) into the agent system prompt without… https://www.cve.org/CVERecord?id=CVE-2026-27001

    Post summary

    The text only states that OpenClaw previously embedded the current working directory in its system prompt, without providing exploit details, patches, or evidence of active use.

    00000107
    56.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27001 Path Traversal Vulnerability in OpenClaw AI Assistant Prior to 20... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27001 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet discloses a path‑traversal vulnerability in OpenClaw AI Assistant (CVE‑2026‑27001) and points to a details page, but does not provide PoC, exploit code, or patch information.

    0000042
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more