'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments
Summary
Security vulnerabilities called 'Claw Chain' were found in OpenClaw, a framework for building AI agents (programs that can perform tasks autonomously). These vulnerabilities allowed attackers to steal login credentials, gain higher-level access to systems, and stay hidden in compromised systems for extended periods. The vulnerabilities have now been patched.
Solution / Mitigation
The vulnerabilities have been patched. Users should update to the patched version of OpenClaw.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.darkreading.com/application-security/claw-chain-vulnerabilities-threaten-openclaw
First tracked: May 18, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 75%