Skip to content

OpenClaw · 2026-03

OpenClaw CVE-2026-31992

An allowlist bypass scored 9.9 on CVSS and was described as a full guardrail bypass.

Last updated 2026-03
Not verified

What the sources report

The sources report an allowlist bypass with a CVSS score of 9.9.

It is described as a full guardrail bypass.

Root cause class

Guardrail bypass

Covered by

What ShipReady can say

Cost caps and output validation sit inside AI features. They stay Not verified until the code is read.

Sources

Check your app

Run all sixteen groups on your published address and see the evidence behind every result.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026