CVE 4.8 MEDIUM

OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputs_CVE-2026-27576

4.8 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Description

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the ACP bridge accepts very large prompt text blocks and can assemble oversized prompt payloads before forwarding them to chat.send. Because ACP runs over local stdio, this mainly affects local ACP clients (for example IDE integrations) that send unusually large inputs. This issue has been fixed in version 2026.2.19.

Basic Information

ID CVE-2026-27576
Source GitHub_M
Published Feb 21, 2026 at 10:00

Affected Product

Vendor openclaw
Product openclaw
Version < 2026.2.19
Affected Versions openclaw openclaw < 2026.2.19

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.