https://shipreadyai.dev/incidents/openclaw-cve-2026-31992

> Discover all available pages from the documentation index at https://shipreadyai.dev/llms.txt

# OpenClaw CVE-2026-31992

2026-03. OpenClaw.

## What happened

The sources report an allowlist bypass with a CVSS score of 9.9.
It is described as a full guardrail bypass.

## What ShipReady can say

Cost caps and output validation sit inside AI features. They stay Not verified until the code is read.

## Sources

- [crackr.dev vibe coding failures](https://crackr.dev/vibe-coding-failures)
