update
Apr 14, 2026
By Teun
OpenClaw 2026.4.14 Focuses on Security After a Rough April
After 13 CVEs were disclosed in April, the team shipped a hardening release with 50+ fixes. The update also adds GPT-5.4 Pro support, better Telegram forum topic handling, and core performance refactors.
OpenClaw has shipped version 2026.4.14, a security-focused release that follows a month in which 13 CVEs were disclosed, including two critical issues. According to the project, the update includes more than 50 fixes and puts hardening ahead of new features, which is the right priority after a run of serious disclosures.
The biggest changes are in the Gateway tool path. The team said earlier versions had gaps in how tool results were validated, which could allow a crafted response to slip past security checks, and this release tightens that logic so results are checked more carefully before they are accepted.
⚡ New to this?
OpenClaw is an automation platform for agents and tools, and this release matters because it fixes security issues after 13 CVEs, or publicly disclosed vulnerabilities, were reported in April. A Gateway is the part that passes tool requests and results between systems, so validation bugs there can have real security impact. The update also adds support for GPT-5.4 Pro and improves Telegram topic handling, which affects people using OpenClaw in production workflows.
🦞 OpenClaw angle
If you run OpenClaw in production, prioritize upgrading to 2026.4.14 and treat it as a security patch, not just a feature release. Review any custom tool passthrough logic or allowlists you maintain, and make sure your own naming and trust rules are exact rather than fuzzy. After the upgrade, test agent flows that rely on the Gateway path and Telegram forum topics, because changes in validation and topic naming can surface integration assumptions you did not know you had.
OpenClaw also changed how trusted tool passthrough is matched. Instead of loose name matching, the release now anchors trust to exact registered names, which reduces the chance that an attacker can smuggle something through by using a near match or a confusing label.
The security work is broad, not just one fix. The release notes describe the update as a hardening pass across the core system, which suggests the team used the April disclosures to clean up related weak points rather than patching only the headline issues.
There are a few functional changes too. OpenClaw 2026.4.14 adds forward-compatible support for GPT-5.4 Pro, improves Telegram forum topic handling, and makes topic names human-readable inside agents instead of exposing abstract thread IDs. That last change matters for operators who want clearer traces when agents interact with threaded discussions.
The performance work is less visible but still useful. The team also folded in core refactors aimed at improving efficiency, which matters for self-hosted deployments where agent throughput and response time can be constrained by the surrounding stack. According to the release notes, the next concrete step is to move older OpenClaw instances to 2026.4.14 rather than leaving exposed systems on earlier vulnerable builds.