CVE-2026-26320: OpenClaw macOS deep link confirmation truncation can conceal executed agent message

Published Feb 17, 2026
·
Updated

Summary OpenClaw macOS desktop client registers the openclaw:// URL scheme. For openclaw://agent deep links without an unattended key, the app shows a confirmation dialog that previously displayed only the first 240 characters of the message, but executed the full message after the user clicked "Run".

At the time of writing, the OpenClaw macOS desktop client is still in beta.

An attacker could pad the message with whitespace to push a malicious payload outside the visible preview, increasing the chance a user approves a different message than the one that is actually executed.

Impact If a user runs the deep link, the agent may perform actions that can lead to arbitrary command execution depending on the user's configured tool approvals/allowlists. This is a social-engineering mediated vulnerability: the confirmation prompt could be made to misrepresent the executed message.

Affected Versions - OpenClaw macOS desktop client versions >= 2026.2.6 and <= 2026.2.13.

Fixed Versions - 2026.2.14.

Mitigations - Do not approve unexpected "Run OpenClaw agent?" prompts triggered while browsing untrusted sites. - Use unattended deep links only with a valid key for trusted personal automations.

Resolution Unkeyed deep links now enforce a strict message length limit for confirmation and ignore delivery/routing knobs (deliver, to, channel) unless a valid unattended key is provided.

Fix commit: 28d9dd7a772501ccc3f71457b4adfee79084fe6f

---

Fix commit 28d9dd7a772501ccc3f71457b4adfee79084fe6f confirmed on main and in v2026.2.14. Upgrade to openclaw >= 2026.2.14.

Other sources

OpenClaw is a personal AI assistant. OpenClaw macOS desktop client registers the openclaw:// URL scheme. For openclaw://agent deep links without an unattended key, the app shows a confirmation dialog that previously displayed only the first 240 characters of the message, but executed the full message after the user clicked "Run." At the time of writing, the OpenClaw macOS desktop client is still in beta. In versions 2026.2.6 through 2026.2.13, an attacker could pad the message with whitespace to push a malicious payload outside the visible preview, increasing the chance a user approves a different message than the one that is actually executed. If a user runs the deep link, the agent may perform actions that can lead to arbitrary command execution depending on the user's configured tool approvals/allowlists. This is a social-engineering mediated vulnerability: the confirmation prompt could be made to misrepresent the executed message. The issue is fixed in 2026.2.14. Other mitigations include not approve unexpected "Run OpenClaw agent?" prompts triggered while browsing untrusted sites and usingunattended deep links only with a valid key for trusted personal automations.

NVD

Affected Software

3 affected componentsFixes available
npm/openclaw>=2026.2.6-0<2026.2.14
2026.2.14
All of the following
OpenClaw Openclaw Node.js>=2026.2.6<2026.2.14
Apple macOS

Event History

Feb 17, 2026
Advisory Published
via GitHub·09:41 PM
Data Sourced
via GitHub·09:41 PM
DescriptionWeaknessAffected Software
Feb 19, 2026
CVE Published
via MITRE·10:24 PM
Data Sourced
via MITRE·10:24 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 4, 58123
Event
via FIRST·08:40 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-26320?

CVE-2026-26320 is classified with a moderate severity due to its potential for executing malicious messages without proper user consent.

2

How do I fix CVE-2026-26320?

To resolve CVE-2026-26320, upgrade to the OpenClaw version 2026.2.14 or later.

3

What systems are affected by CVE-2026-26320?

CVE-2026-26320 affects the OpenClaw macOS desktop client versions from 2026.2.6-0 up to but not including 2026.2.14.

4

What vulnerability does CVE-2026-26320 exploit?

CVE-2026-26320 exploits the handling of the 'openclaw://' URL scheme, particularly with deep links lacking an unattended key.

5

What are the implications of CVE-2026-26320?

If exploited, CVE-2026-26320 could allow attackers to execute unintended commands or actions through the full message execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203