Openclaw cli: OpenClaw log poisoning (indirect prompt injection) via WebSocket headers
Description
OpenClaw CLI versions prior to 2026.2.13 log certain WebSocket request headers without sanitization or length limits when connections close before completing the handshake. This can allow unauthenticated clients to inject crafted header values into logs. If these logs are later processed by AI-assisted debugging tools or LLMs, this may lead to indirect prompt injection (log poisoning). The issue is fixed in version 2026.2.13 by sanitizing and truncating header values before logging.
CVSS v3.1
Score 3.1low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In openclaw versions <= 2026.2.12, the gateway logs certain WebSocket headers such as Origin and User-Agent without neutralization or length restrictions when the connection closes prematurely. An unauthenticated client can send crafted headers that get logged, potentially enabling indirect prompt injection if logs are consumed by LLM-based tools. The vulnerability is addressed in version 2026.2.13 by sanitizing and truncating logged header values, removing control characters and limiting length.
Potential Impact
The primary impact is an indirect prompt injection risk via log poisoning, which depends on downstream usage of logs by AI-assisted debugging or LLMs. There is no direct compromise of confidentiality, integrity, or availability of the system. If logs are not fed into LLMs or similar automation, the impact is minimal.
Mitigation Recommendations
Upgrade to openclaw version 2026.2.13 or later where the issue is fixed. Until then, treat logs as untrusted input when using AI-assisted debugging by sanitizing or escaping log content and avoid auto-executing instructions derived from logs. Additionally, restrict gateway network exposure and apply reverse-proxy limits on header size to reduce risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-GHSA-g27f-9qjv-22pm
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6ac2458512601ec6a3164089
Added to database: 10/04/2026, 12:24:37 UTC
Last enriched: 10/04/2026, 12:31:34 UTC
Last updated: 10/04/2026, 12:31:34 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.