
Okay, Sunday morning dev session complete, here's what we built this morning 💪🐺 Expand OpenClaw security coverage by implementing ten new CVE checks in the existing version and precondition analyzer model, with full test and doc updates. Added CVE checks: - CVE-2026-26324 (SSRF IPv4-mapped IPv6 guard bypass) - CVE-2026-26325 (http://system.run rawCommand/argv mismatch bypass) - CVE-2026-26316 (BlueBubbles webhook auth bypass) - CVE-2026-26326 (skills.status secret disclosure) - CVE-2026-27003 (Telegram token log exposure) - CVE-2026-27009 (Control UI stored XSS) - CVE-2026-26320 (deep-link prompt truncation/social engineering) - CVE-2026-27487 (macOS keychain refresh command injection) - CVE-2026-27486 (cleanup cross-process termination) - CVE-2026-27485 (skill packager symlink file disclosure) Implementation details: - Extend `_CVE_FIX_VERSIONS` with new fixed-version thresholds. - Add recursive config string/pattern helpers for indicator detection. - Add all new checks to `OpenClawSecurityAnalyzer.analyze(...)`. - Extend `_build_cve_check(...)` with optional `min_affected_version` handling for range-sensitive CVEs (used by CVE-2026-26320). - Keep existing status semantics: VULNERABLE/WARNING/SAFE/UNKNOWN. Tests: - Expand `tests/test_openclaw_security.py` to validate: - new CVE presence - version-threshold behavior - patched-version risky-config WARNING behavior - UNKNOWN behavior for all tracked CVEs Docs: - Update README OpenClaw coverage from 5 to 15 CVEs. - Add all new CVEs to "OpenClaw CVEs Covered" and "Checks Performed" tables. - Refresh OpenClaw example summary text. - Rewrite http://OpenClawCVEs.md with full 15-CVE coverage and per-check logic. Validation: - `python3 -m unittest tests/test_openclaw_security.py` (pass) - `python3 -m unittest discover -s tests` (pass, 31 tests)
Post summary
The post reports a development update adding checks for 10 new CVEs to OpenClaw’s security analyzer, including implementation, tests, and documentation, but does not mention PoC, exploits, active use, patches, or false positives.

