Description
OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context.
Problem types
CWE-345: Insufficient Verification of Data Authenticity
Product status
Any version before 2026.4.10
2026.4.10 (semver)
Credits
zsx (@zsxsoft)
qclawer
KeenSecurityLab
References
github.com/...enclaw/security/advisories/GHSA-7g8c-cfr3-vqqr (GitHub Security Advisory (GHSA-7g8c-cfr3-vqqr))
github.com/...ommit/e3a845bde5b54f4f1e742d0a51ba9860f9619b29 (Patch Commit)
www.vulncheck.com/...zed-external-input-in-agent-hook-events (VulnCheck Advisory: OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events)