OpenClaw 2026.5.27 tightens security and release checks

OpenClaw 2026.5.27 adds stronger security boundaries, blocks unsafe command and runtime settings, and improves delivery behavior across channels such as Slack, Telegram, iMessage, and Discord. The release also expands provider support, including OpenAI-compatible embeddings and Pixverse video generation, while hardening packaging, CI, and release verification.

OpenClaw 2026.5.27 tightens security and release checks

OpenClaw 2026.5.27, released on 28 May, focuses heavily on security boundaries, delivery reliability, and release hardening across the platform. The release notes say the update includes multiple fixes that reduce the chance of untrusted data reaching sensitive prompts or commands, while also tightening approval flows and channel-specific behavior.

On the security side, OpenClaw says it now keeps group prompt text out of the system prompt, normalizes hostnames with repeated trailing dots, blocks side-effecting command wrappers, and rejects unsafe Node runtime environment overrides. The release also rejects no-auth Tailscale exposure, blocks untrusted Microsoft Teams service URLs, enforces an origin policy for /allowlist config writes, and requires admin authority for node and device-role approvals.

⚡ New to this?

This release matters because it changes how OpenClaw separates trusted instructions from untrusted input. In plain terms, prompts are the text sent to the AI, and a system prompt is the highest-priority instruction set; keeping group prompt text out of it reduces the chance that outside content can steer the agent. It also tightens approvals and command handling, which affects whether an automation can run actions or expose services safely.

🦞 OpenClaw angle

If you run OpenClaw with custom plugins or self-hosted agents, review any code that injects group metadata into prompts and move that data into a lower-trust field instead. Audit command wrappers, Node env overrides, and Tailscale exposure settings for anything that could bypass approval checks. If you build channel automations, retest Slack, Telegram, Discord, Matrix, iMessage, and Google Chat flows after upgrading, since several delivery and approval paths changed.

The project also tightened approval handling in a few places. According to the release notes, QQBot fallback approval buttons are now gated, Discord guild requester checks are stricter, and node/device-role approvals now require admin authority. These changes are part of a broader effort to keep untrusted metadata and low-trust requests from crossing security boundaries inside the system.

Several Codex-related runtime issues were addressed as well. OpenClaw says Codex runtime models now resolve before generic routing, workspace memory is routed through tools, shared app-server clients survive startup and spawned-helper failures, and native hook relay generations persist across restarts and fresh fallbacks. The release also says it avoids false runtime live switches and keeps raw reasoning and source-reply guards intact.

Channel delivery received a long list of fixes. Telegram sendMessage actions now use durable outbound delivery, iMessage suppresses duplicate native exec approval prompts and sends, Slack keeps delivered final replies during late cleanup, Matrix mention previews and finals are stricter, Discord suppresses recovered tool-warning artifacts from successful replies, and Google Chat no longer sends threads in direct messages. The release notes also say QQBot approval buttons now honor slash-command auth.

Provider and model coverage was expanded too. OpenClaw added a core OpenAI-compatible embedding provider for local and hosted endpoints, with config, doctor, and documentation support. It also added the Pixverse video generation provider with API region selection, and improved DeepInfra browsing so users see the full credential-aware catalog during onboarding.

Other provider changes include support for VLLM thinking parameters, Claude CLI OAuth overlays for PI auth profiles, and bare direct Anthropic model IDs. The release notes also mention better handling for OpenAI-compatible chat completions, OpenAI Responses replay tool IDs, and cache retention behavior.

OpenClaw says it also hardened its packaging and verification path. The update improves npm and package inventory handling, shrinkwrap override merging, Docker runtime workspace templates, release postpublish checks, beta smoke checks, and E2E log and probe waits. The release verification links include npm, registry tarball, and multiple GitHub Actions runs for preflight, validation, checks, performance, and macOS signing and notarization.

The release is available as OpenClaw 2026.5.27 on npm and through the project’s macOS downloads and appcast feeds.

Source: OpenClaw Releases ↗

More from Security News