Three merges on OpenClaw main rework how reusable exec approvals, recurring cron automations, and MCP App grants hold authority — with one breaking change that deactivates older generated approvals until you re-approve in the intended directory.
6 min read6 primary sourcesVerified 26 Aug 2026Read analysis →
Two P0 fixes landed on OpenClaw main within hours of each other: public plugin ingress could claim owner privileges, and agents could spin up Gateway terminals that ignored session permissions. Here is what changed and what operators should do.
4 min read4 primary sourcesVerified 26 Aug 2026Read analysis →
Main-branch fixes stop Ollama cloud credentials being forwarded to loopback aliases, redact reflected API keys from provider errors, and keep ngrok auth tokens out of process arguments.
4 min read4 primary sourcesVerified 25 Aug 2026Read analysis →
A merged fix stops ambient environment variables from silently satisfying Feishu provider authorization when the configured SecretRef policy disallows them — closing a gap that let denied credentials reach document comments and directory lookups.
2 min read1 primary sourceVerified 24 Aug 2026Read analysis →
Merged PR #127699 makes Gateway runtime snapshots the sole owner of memory SecretRef materialization and stops embedding credentials, Authorization headers, and tenant headers from following requests to different endpoints — including query-distinct tenants on the same host.
2 min read1 primary sourceVerified 24 Aug 2026Read analysis →
A bare suffix match treated look-alike hosts such as evil1drv.ms as OneDrive and SharePoint share links, routing them into Graph authentication. Merged fixes require a dot boundary, HTTPS, and keep look-alike downloads out of the Graph auth path.
4 min read2 primary sourcesVerified 23 Aug 2026Read analysis →
openclaw skills update passed force:true unconditionally, replacing locally modified skill directories and deleting their backups. A merged fix verifies digests first and preserves local changes.
3 min read2 primary sourcesVerified 22 Aug 2026Read analysis →
Broad diagnostic redaction rewrote source code inside tool results, corrupting later reads and edits. A merged fix confines redaction to diagnostics while preserving the security boundary.
3 min read2 primary sourcesVerified 22 Aug 2026Read analysis →
Merged main fixes stop approvals --json from printing the exec-approvals socket token in cleartext and stop removed Claw agents from leaving their approval policies behind for the next agent with the same id.
4 min read3 primary sourcesVerified 22 Aug 2026Read analysis →
Merged main change stops external plugin tools from reaching the raw outbound adapter, adds an optional current-turn-only delivery.send capability, and revokes send authority at turn closure.
4 min read2 primary sourcesVerified 21 Aug 2026Read analysis →
Three merged OpenClaw fixes close plaintext gateway credential writes, silent ref-mode token leaks, and secret exposure in onboarding failure output. Here is what operators should audit on installs made before the fixes.
5 min read4 primary sourcesVerified 21 Aug 2026Read analysis →
Shared bots can isolate MCP credentials by trusted sender, but operators must explicitly choose the new identity mode, configure a public callback origin and accept a shared-channel sign-in-link tradeoff.
4 min read1 primary sourceVerified 12 Aug 2026Read analysis →
A recurring no-payload Telegram failure is still unresolved; separately, main now prevents provider-confirmed exact sends from remaining ambiguous and replaying after restart.
4 min read2 primary sourcesVerified 12 Aug 2026Read analysis →
A security-boundary fix stops stored MCP refresh tokens being replayed to a different authorization server; older token-only rows may require one clean reauthorization.
4 min read3 primary sourcesVerified 11 Aug 2026Read analysis →
The extension is now browser-automation infrastructure with a local native-messaging bootstrap; Linux and macOS operators still load it once, while Windows keeps manual pairing.
4 min read3 primary sourcesVerified 11 Aug 2026Read analysis →
The team-scoped store now has Control UI management and stricter value validation; write-only secrets remain separate from env values exposed to agent subprocesses.
5 min read6 primary sourcesVerified 11 Aug 2026Read analysis →
Gateway scopes, internal turns, channel approvals and delegated retries now carry canonical owner context instead of reconstructing authority from transport-shaped or client-visible data.
3 min read5 primary sourcesVerified 11 Aug 2026Read analysis →
A P1 fix keeps context-excluded shell output out of replay and compaction, while Telegram now respects disabled tool progress even when verbose mode is on.
4 min read3 primary sourcesVerified 10 Aug 2026Read analysis →
Managed updates could finalise against the caller's profile, chat history could expose raw audio or local paths, and Telegram DM tool policy could be skipped on queued or native runs.
4 min read4 primary sourcesVerified 9 Aug 2026Read analysis →
Browser relay auth, subagent tool denial, gateway URL redaction, credential-safe prompts and retirement of inline hook handlers tighten different trust boundaries. One requires a manual migration before Doctor cleanup.
4 min read6 primary sourcesVerified 9 Aug 2026Read analysis →
The extended-stable selector moved to 2026.6.34 with security, delivery, provider and local-runtime hardening. Here is the operator decision, the migration warning and what to verify.
4 min read2 primary sourcesVerified 9 Aug 2026Read analysis →
Registered Git worktrees placed directly under OpenClaw's worktrees root could be recursively cleaned as orphans; a landed fix now preserves registered checkout roots.
4 min read4 primary sourcesVerified 6 Aug 2026Read analysis →
Merged Telegram repairs route reactions through their real forum topic, persist polling progress safely and correlate outbound delivery to the explicit topic.
5 min read4 primary sourcesVerified 4 Aug 2026Read analysis →
The workspace override moved from vulnerable 5.0.8 to 5.0.9 after GitHub advisory GHSA-rgw5-rvv9-x895; source-build operators should verify the resolved dependency.
3 min read2 primary sourcesVerified 3 Aug 2026Read analysis →
Merged fixes isolate OpenRouter, memory, Ollama, LanceDB, Bedrock and Google credentials while preventing referenced secrets and provider keys from reaching plaintext logs.
6 min read10 primary sourcesVerified 6 Aug 2026Read analysis →
Merged Memory Wiki fixes enforce conversation visibility in search, preserve handwritten notes during damaged rebuilds and keep QMD available when filesystem watches fail.
4 min read4 primary sourcesVerified 3 Aug 2026Read analysis →
Control UI actions now follow Gateway scopes and parameters, while host-issued dashboard handoffs deliberately bootstrap a durable owner credential with administrator access.
6 min read3 primary sourcesVerified 6 Aug 2026Read analysis →
Two merged Telegram fixes move account, topic and command authorization ahead of media ingestion so rejected group commands cannot trigger attachment downloads.
4 min read2 primary sourcesVerified 2 Aug 2026Read analysis →
Merged main fixes preserve cancellation and rewrites across restart while waking persisted channel retries after their backoff without duplicate delivery.
7 min read5 primary sourcesVerified 5 Aug 2026Read analysis →
A new main-branch inference contract gives plugins a fresh, text-only model call with zero tools, explicit model authorization and fail-closed runtime support.
5 min read5 primary sourcesVerified 30 Jul 2026Read analysis →
A merged scanner fix reports every distinct process-execution match in a plugin file, closing a review gap where only the first executable call was shown.
4 min read2 primary sourcesVerified 30 Jul 2026Read analysis →
A merged OpenClaw security fix makes scheduled runs fail closed when their recorded channel account has been removed instead of falling through to unrestricted tools.
4 min read2 primary sourcesVerified 30 Jul 2026Read analysis →
Two merged fixes tighten the external-hook boundary: untrusted job names stay inside fenced content, while Codex relay work now follows explicit tool matchers.
5 min read3 primary sourcesVerified 29 Jul 2026Read analysis →
A merged main-branch fix stops Matrix rooms or Signal groups whose opaque IDs differ only by case from sharing transcripts and control state in the web UI.
4 min read2 primary sourcesVerified 27 Jul 2026Read analysis →
A merged main-branch P1 fix stops automatic execution review from approving Windows cmd launches that can run hidden AutoRun or persistent-shell commands.
4 min read2 primary sourcesVerified 27 Jul 2026Read analysis →
A merged main-branch security fix stops exec allowlist analysis from approving a shell word whose escaped newline can create a different POSIX command boundary.
4 min read2 primary sourcesVerified 27 Jul 2026Read analysis →
Two merged main-branch changes retire legacy auth and exec-approval JSON runtime stores, add fail-closed migration gates and make Doctor the supported importer.
6 min read2 primary sourcesVerified 26 Jul 2026Read analysis →
A merged Control UI change makes the admin-scoped host terminal default-on. Operators who do not want browser PTY access should set the explicit opt-out before upgrading.
5 min read1 primary sourceVerified 26 Jul 2026Read analysis →
A security fix on OpenClaw main makes Vault and 1Password secret-plan writes exclusive and owner-only. Operators should protect old plans and verify the containing release.
4 min read2 primary sourcesVerified 25 Jul 2026Read analysis →
Claude CLI sessions under restrictive policy can now request human approval for native and extension tools instead of silently denying them, with Bash and timeout paths kept fail-closed.
5 min read1 primary sourceVerified 24 Jul 2026Read analysis →
A merged OpenClaw fix preserves creator-authorized Cron tool caps across scheduled, CLI and cloud-worker execution without letting the cap override current safety policy.
7 min read3 primary sourcesVerified 24 Jul 2026Read analysis →
Prompt injection is not solved. Learn five attack patterns and how OpenClaw reduces blast radius with pairing, sandboxing, agent isolation and strict tool policy.
8 min read7 primary sourcesVerified 10 Aug 2026Read analysis →