CVE-2026-27524Disclosure(openclaw / openclaw)

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowing prototype pollution attacks. Authorized /debug set callers can inject __proto__, constructor, or prototype keys to manipulate object prototypes and bypass command gate restrictions.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-18: 3Technical Details · 2026-03-18: 203-18
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27524 Prototype Pollution Vulnerability in OpenClaw Versions Before 2026.2.21 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27524

    Post summary

    A prototype pollution vulnerability was disclosed for OpenClaw before version 2026.2.21; no PoC, exploit code, or patch information was mentioned.

    0001044
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-27524 📊 Severity: 3.1 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-27524 #CVE-2026-27524 #CVE #Low  #CyberSecurity #InfoSec https://t.co/2YUXOuR6Oq

    Post summary

    The tweet merely announces a low‑severity CVE with a link to its NVD entry, offering no further technical, exploit, or mitigation details.

    0000034
    104 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27524 OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowing prototype pollution attacks. Authorized /de… https://www.cve.org/CVERecord?id=CVE-2026-27524

    Post summary

    CVE‑2026‑27524 is a prototype‑pollution vulnerability affecting OpenClaw prior to version 2026.2.21, exploitable via the /debug set override mechanism, but no PoC, exploit code, or active exploitation is reported.

    0000080
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more