OpenClaw hardens transcripts, channels, and security boundaries

OpenClaw’s 2026.5.26 update adds a faster Gateway path, broader transcript handling, and stronger content-boundary checks. The release also improves Telegram, iMessage, WhatsApp, Discord, Signal, voice features, installs, and diagnostics.

OpenClaw hardens transcripts, channels, and security boundaries

OpenClaw 2026.5.26 focuses on making the Gateway faster, transcript handling more reliable, and message-channel behavior closer to production use. The update also adds multiple security fixes around content boundaries, prompt-like text, browser reads, and device-token handling, according to the release notes.

On the performance side, OpenClaw said startup now avoids repeated plugin, channel, session, usage-cost, warning, scheduled-service, and filesystem scans. That reduces churn in Gateway runtime and session caches under load, and should make replies faster because visible user-facing sends are separated from slower follow-up work.

⚡ New to this?

This release matters because it touches the pieces that make an AI automation system usable in practice: speed, reliability, and safety. A Gateway is the router that handles agent requests, and transcripts are the stored records of chats, tool calls, and replies that let the system summarize or replay work later. It also adds protections against SSRF, or Server-Side Request Forgery, which is a class of attack where a system is tricked into fetching internal or unsafe resources.

🦞 OpenClaw angle

If you run self-hosted agents, review your content-boundary rules now: keep browser fetches, file reads, and inbound message sources behind explicit allowlists and SSRF checks. Move any workflow that depends on summaries, replay, or follow-up actions onto the new transcript-backed paths so failures do not lose context.

If you use approvals in mobile channels, test the new reaction-based flows in Telegram, iMessage, WhatsApp, and Signal so operators do not have to fall back to manual /approve text commands. Also turn on the new rate limiting and inspect the Activity tab and LLM spans so you can spot auth abuse, stale sessions, and tool failures before they cascade.

The release also makes transcripts a core path for more of the product. According to the changelog, transcript-backed meeting summaries, source-provider chunks, cleaned user turns, media provenance, Codex mirrors, WebChat replies, and CLI/TUI replay all now use a more reliable transcript flow.

Channel support saw a broad set of fixes. OpenClaw said Telegram keeps typing and progress context, iMessage now handles attachment roots and duplicate local Messages sources, WhatsApp restores group and media behavior, Discord improves voice playback and model picking, and Signal, iMessage, and WhatsApp all get reaction approvals.

Voice features were expanded as well. The company said realtime Talk runs can now be inspected, steered, cancelled, or followed up from the Web UI and Discord voice paths. It also said wake-name handling is more tolerant, while ambient speech is still kept from triggering agents.

Security-related changes are a major part of the release. According to the notes, browser snapshot reads now honor SSRF policy, system-event text cannot spoof nested prompt markers, fetched file text is wrapped as external content, ClickClack sender allowlists run before agent dispatch, stale device tokens are rejected, and serialized tool-call text is scrubbed from replies.

OpenClaw also changed provider and model behavior. The company said named auth profiles, OpenAI sampling parameters, Codex app-server resume and timeout recovery, dynamic tool-schema guards, xAI usage-limit surfacing, Ollama top-p normalization, and local approval resolution reduce provider-specific dead ends.

Install, release, and update paths were hardened too. The release notes mention Alpine installs, trusted runtime fallback roots, stable update channels, Docker and package timeouts, Windows Scheduled Tasks, Windows and macOS proof lanes, Testbox and Crabbox delegation, plugin publish checks, and macOS runner bootstraps.

Diagnostics were widened across the stack. OpenClaw said the Activity tab, Gateway secret-prep traces, tool and model stream progress, explicit fast-mode status, systemd Gateway hygiene, OpenTelemetry LLM spans, release performance evidence, and richer telemetry should make failures easier to inspect.

Among the specific fixes, OpenClaw said it now rejects prompt-like text submitted through the explicit memory_store tool before embedding or storage. It also enabled the default auth rate limiter for remote non-browser and HTTP Gateway auth failures when gateway.auth.rateLimit is unset, while keeping the loopback exemption in place.

The update also includes a small but notable scheduling change: cron.maxConcurrentRuns now defaults to 8, so scheduled automations and their isolated agent turns can run in parallel without extra configuration, according to the changelog.

Source: OpenClaw Releases ↗

More from Security News