Skip to content

ai-security

OpenClaw agents kept reading memory after it was disabled

Promtime

Suppose an operator turned off memory access while an OpenClaw agent was in the middle of a run. The agent could keep reading memory until the run finished. That is one of the findings in OpenClaw's write-up of its security audit by Trail of Bits, which ran through OpenAI's Patch the Planet initiative and produced 27 private advisories, none rated Critical.

At a glance

  • Trail of Bits reviewed OpenClaw's core permissions and its handling of user data, then sent 27 private repository advisories and 3 standalone hardening pull requests, all three of which OpenClaw merged.
  • The 24 severity-rated reports came out 0 Critical, 2 High, 16 Medium and 6 Low. The other 3 were defense-in-depth findings that crossed no documented trust boundary.
  • OpenClaw describes the bug classes in detail but does not say which two findings earned the High rating, and it closed some advisories without publication because the fixes landed before a stable release.

In case you haven't been following OpenClaw: according to DEV Community, it started in November 2025 as "Clawdbot", a self-hosted AI assistant built by Peter Steinberger with terminal access, file system control and the ability to run multi-step workflows on its own. The same outlet says it was renamed Moltbot on January 27, 2026, and then OpenClaw on January 30, 2026. Nxcode reports that OpenAI announced Patch the Planet with Trail of Bits on June 23, 2026.

Trail of Bits filed 27 advisories, and OpenClaw confirmed 23 as vulnerabilities

Of the 27 private repository advisories, 24 described severity-rated vulnerabilities. OpenClaw classified 23 of those as confirmed vulnerabilities. The remaining one concerned a bug that had already been fixed before Trail of Bits submitted it. Some of the confirmed reports were closed without publication because the flaw was fixed before it ever reached a stable release.

Across those 24 reports, the ratings were 0 Critical, 2 High, 16 Medium and 6 Low. The last 3 advisories were defense-in-depth findings. They got no severity rating because they did not cross a documented trust boundary. Trail of Bits also sent 3 standalone hardening pull requests. OpenClaw says it has repaired every actionable issue and merged all three of those PRs.

Codex helped find and fix the bugs, and Trail of Bits engineers checked each one by hand

Patch the Planet pairs AI-assisted security research with human review. Trail of Bits used Codex-assisted workflows to look for issues and draft fixes, then checked the findings manually before sending them to OpenClaw. OpenClaw weighed each report against its trust model and release history. It then fixed and tested the accepted issues and coordinated disclosure through private GitHub Security Advisories.

OpenClaw thanks Samuel Judson, Lucas Bourtoule, the wider Trail of Bits team and OpenAI. According to Nxcode, the wider program screens findings before they reach maintainers and sends pull requests with fixes, tests, fuzzing harnesses, CI improvements and supply-chain hardening. Maintainers decide what gets merged. The same outlet says the goal is to avoid flooding maintainers with plausible-looking AI bug reports. It also cites Trail of Bits' week-one tally of 19 projects, 64 pull requests, 51 issues and 37 merged patches.

Permissions got lost between steps, the most common of four recurring patterns

The review covered OpenClaw's core permissions and how it handles user data across its features. The affected features varied, but OpenClaw says the same kinds of security problems kept coming back. It groups them into four patterns.

The most common was permissions getting lost between steps. A request would arrive with limited access and then start follow-on work that no longer carried those limits. Think of a visitor badge that stays at the front desk when the visitor is passed to another department. Sometimes the fix was to pass the original permissions along. In other cases the follow-on work never needed access at all. OpenClaw's example is a filename generator, which has no use for tools.

The second pattern was about names. OpenClaw keeps some older names for user identities and features so that existing configurations still work. A security check could approve one name while the system later used another. The fix works out exactly which name the system will use before the security policy is applied.

One file path changed after approval, and one memory setting changed during a run

The third pattern was a gap between what was checked and what was later used. One check inspected only part of an archive before the full contents were extracted. In another case, a file path changed after OpenClaw had approved it. Security engineers call this a time-of-check to time-of-use gap. The repair ties approval to the exact file, identity or action that will be used, and checks again if anything changes.

The fourth pattern was permission changes that never reached work already in progress. An agent can keep working long after a request begins, so a check at launch is not enough. A run that started with memory access enabled could keep reading memory after the operator disabled it. It is like a revoked key card that still opens a door someone propped open. Tools now check the current setting every time they act.

OpenClaw notes that the memory bug only affected runs that had already been given access. Its own lessons add a point about testing: tests should exercise the real security boundary instead of stopping at the helper where a bug happened to show up.

What the write-up leaves out

The write-up is generous with patterns and sparing with specifics. It does not say which two findings were rated High, which features they touched, or how long any of them were present in shipped versions. Oddly, the name problem comes from a deliberate compatibility choice, keeping old names so older configurations still work, and the post does not say whether those older names will ever be removed. On that reading, the same kind of bug could likely come back.

Upgrading to 2026.8.1 or 2026.7.33 LTS

For operators, the version number is the thing to check. Every fix is on main and ships in the 2026.8.1 and 2026.7.33 LTS stable releases. OpenClaw has not named the two High-severity findings or said whether it will publish more of the advisory text, and it has given no date for further disclosure.

Related stories

  1. Codex Security Cloud reviews commits with the laptop closed
  2. OpenAI's agent audit costs over $500,000 a day
  3. OpenAI's rogue-agent warnings reach more than 100 groups
  4. OpenAI agent got into a second NSW site with fire data
  5. Prompt injections can spread like worms, OpenAI shows
  6. At least 53 times, OpenAI agents moved users' images

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.