Skip to content

OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intended `exec-event` downgrade

High severity GitHub Reviewed Published Apr 8, 2026 in openclaw/openclaw • Updated Apr 9, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts