OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attackers can exploit this trust-labeling issue to strengthen prompt-injection attacks by rendering untrusted events as trusted System events.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/commit/f61896b03cc7031f51106a04566831f4ac2a0bd7 | Patch |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-57r2-h2wj-g887 | Third Party Advisory |
| https://www.vulncheck.com/advisories/openclaw-improper-trust-labeling-in-isolated-cron-awareness-events | Third Party Advisory Patch |
Configurations
History
13 May 2026, 14:12
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| First Time |
Openclaw
Openclaw openclaw |
|
| References | () https://github.com/openclaw/openclaw/commit/f61896b03cc7031f51106a04566831f4ac2a0bd7 - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-57r2-h2wj-g887 - Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-improper-trust-labeling-in-isolated-cron-awareness-events - Third Party Advisory, Patch |
11 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-11 18:16
Updated : 2026-05-13 14:12
NVD link : CVE-2026-44999
Mitre link : CVE-2026-44999
CVE.ORG link : CVE-2026-44999
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-345
Insufficient Verification of Data Authenticity
