Openclaw cli: OpenClaw's runtime /debug override path accepted prototype-reserved keys (CVE-2026-27524)
Description
OpenClaw CLI's runtime `/debug set` override functionality accepted prototype-reserved keys such as `__proto__`, `constructor`, and `prototype`. This vulnerability affects runtime in-memory overrides only, which are non-persistent and cleared on restart. The `/debug` command is disabled by default and requires prior authorization to invoke, with no unauthenticated exploitation vector identified. The issue is addressed in the planned release 2026.2.21 by blocking reserved prototype keys during deep merges and sanitizing nested object values. This vulnerability is considered a defense-in-depth hardening measure rather than a critical security flaw.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenClaw CLI versions up to 2026.2.19-2 allowed prototype-reserved keys (`__proto__`, `constructor`, `prototype`) in runtime `/debug set` override objects. This could potentially affect command flag evaluation by enabling inherited prototype properties. However, exploitation requires an authorized caller to `/debug set`, and the `/debug` command is disabled by default. The vulnerability impacts only runtime in-memory overrides, which are cleared on restart and non-persistent. The fix, included in version 2026.2.21, prevents merging of reserved prototype keys and sanitizes nested object values to remove such keys. Restricted commands now require own-property boolean flags to prevent enabling via inherited prototype values.
Potential Impact
The vulnerability affects only authorized users who can invoke the `/debug set` command, which is disabled by default. There is no unauthenticated attack vector. The impact is limited to runtime in-memory overrides that do not persist beyond process restart or reset. This reduces the risk to a defense-in-depth concern related to command flag evaluation rather than a direct security breach or persistent compromise.
Mitigation Recommendations
A patch is available in OpenClaw CLI version 2026.2.21 that addresses this issue by blocking prototype-reserved keys during runtime override merges and sanitizing nested object values. Users should upgrade to version 2026.2.21 or later once released. Since `/debug` is disabled by default and requires authorization, no additional immediate action is required beyond applying the official fix when available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-27524
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac245cc12601ec6a3167f31
Added to database: 10/04/2026, 12:25:48 UTC
Last enriched: 10/04/2026, 13:12:08 UTC
Last updated: 10/04/2026, 16:08:37 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.