CVE-2026-27576: OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputs

Published Feb 20, 2026
·
Updated

Vulnerability

The ACP bridge accepted very large prompt text blocks and could assemble oversized prompt payloads before forwarding them to chat.send.

Because ACP runs over local stdio, this mainly affects local ACP clients (for example IDE integrations) that send unusually large inputs.

Affected Packages / Versions

- Package: openclaw (npm) - Affected versions: <= 2026.2.17 - Patched version: 2026.2.18 (planned next release)

Impact

- Local ACP sessions may become less responsive when very large prompts are submitted - Larger-than-expected model usage/cost when oversized text is forwarded - No privilege escalation and no direct remote attack path in the default ACP model

Affected Components

- src/acp/event-mapper.ts - src/acp/translator.ts

Remediation

- Enforce a 2 MiB prompt-text limit before concatenation - Count inter-block newline separator bytes during pre-concatenation size checks - Keep final outbound message-size validation before chat.send - Avoid stale active-run session state when oversized prompts are rejected - Add regression tests for oversize rejection and active-run cleanup

Fix Commit(s)

- 732e53151e8fbdfc0501182ddb0e900878bdc1e3 - ebcf19746f5c500a41817e03abecadea8655654a - 63e39d7f57ac4ad4a5e38d17e7394ae7c4dd0b9c

Thanks @aether-ai-agent for reporting.

Other sources

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the ACP bridge accepts very large prompt text blocks and can assemble oversized prompt payloads before forwarding them to chat.send. Because ACP runs over local stdio, this mainly affects local ACP clients (for example IDE integrations) that send unusually large inputs. This issue has been fixed in version 2026.2.19.

MITRE

Affected Software

2 affected componentsFixes available
npm/openclaw<=2026.2.17
2026.2.19
OpenClaw Openclaw Node.js<=2026.2.17

Event History

Feb 20, 2026
Advisory Published
via GitHub·09:52 PM
Data Sourced
via GitHub·09:52 PM
DescriptionWeaknessAffected Software
Feb 21, 2026
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionWeakness
Data Sourced
via NVD·10:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 2, 58120
Event
via FIRST·10:54 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-27576?

CVE-2026-27576 is categorized as a medium severity vulnerability due to potential performance impacts from oversized prompt payloads.

2

How do I fix CVE-2026-27576?

To fix CVE-2026-27576, update the OpenClaw package to version 2026.2.19 or later.

3

What does CVE-2026-27576 affect?

CVE-2026-27576 affects OpenClaw versions up to and including 2026.2.17.

4

What is the impact of CVE-2026-27576?

The impact of CVE-2026-27576 is the reduced responsiveness of the system when handling very large inputs.

5

Is CVE-2026-27576 remote exploitable?

CVE-2026-27576 is not remote exploitable as it affects local interactions through the ACP bridge.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203