security
May 28, 2026
By Teun
OpenClaw 2026.5.27 tightens security and release checks
OpenClaw 2026.5.27 adds stronger security boundaries, blocks unsafe command and runtime settings, and improves delivery behavior across channels such as Slack, Telegram, iMessage, and Discord. The release also expands provider support, including OpenAI-compatible embeddings and Pixverse video generation, while hardening packaging, CI, and release verification.
OpenClaw 2026.5.27, released on 28 May, focuses heavily on security boundaries, delivery reliability, and release hardening across the platform. The release notes say the update includes multiple fixes that reduce the chance of untrusted data reaching sensitive prompts or commands, while also tightening approval flows and channel-specific behavior.
On the security side, OpenClaw says it now keeps group prompt text out of the system prompt, normalizes hostnames with repeated trailing dots, blocks side-effecting command wrappers, and rejects unsafe Node runtime environment overrides. The release also rejects no-auth Tailscale exposure, blocks untrusted Microsoft Teams service URLs, enforces an origin policy for /allowlist config writes, and requires admin authority for node and device-role approvals.
The project also tightened approval handling in a few places. According to the release notes, QQBot fallback approval buttons are now gated, Discord guild requester checks are stricter, and node/device-role approvals now require admin authority. These changes are part of a broader effort to keep untrusted metadata and low-trust requests from crossing security boundaries inside the system.
Several Codex-related runtime issues were addressed as well. OpenClaw says Codex runtime models now resolve before generic routing, workspace memory is routed through tools, shared app-server clients survive startup and spawned-helper failures, and native hook relay generations persist across restarts and fresh fallbacks. The release also says it avoids false runtime live switches and keeps raw reasoning and source-reply guards intact.
Channel delivery received a long list of fixes. Telegram sendMessage actions now use durable outbound delivery, iMessage suppresses duplicate native exec approval prompts and sends, Slack keeps delivered final replies during late cleanup, Matrix mention previews and finals are stricter, Discord suppresses recovered tool-warning artifacts from successful replies, and Google Chat no longer sends threads in direct messages. The release notes also say QQBot approval buttons now honor slash-command auth.
Provider and model coverage was expanded too. OpenClaw added a core OpenAI-compatible embedding provider for local and hosted endpoints, with config, doctor, and documentation support. It also added the Pixverse video generation provider with API region selection, and improved DeepInfra browsing so users see the full credential-aware catalog during onboarding.
Other provider changes include support for VLLM thinking parameters, Claude CLI OAuth overlays for PI auth profiles, and bare direct Anthropic model IDs. The release notes also mention better handling for OpenAI-compatible chat completions, OpenAI Responses replay tool IDs, and cache retention behavior.
OpenClaw says it also hardened its packaging and verification path. The update improves npm and package inventory handling, shrinkwrap override merging, Docker runtime workspace templates, release postpublish checks, beta smoke checks, and E2E log and probe waits. The release verification links include npm, registry tarball, and multiple GitHub Actions runs for preflight, validation, checks, performance, and macOS signing and notarization.
The release is available as OpenClaw 2026.5.27 on npm and through the project’s macOS downloads and appcast feeds.