< Back to all clusters
[TECHNOLOGY] · 3 sources

OpenClaw patches critical WhatsApp‑related vulnerabilities and adds new UI features

Security researcher Chinmohan Nayak disclosed three high‑severity flaws in the OpenClaw AI coding assistant (CVSS scores 8.8, 8.8 and 8.4). The vulnerabilities allow an attacker to inject OS commands, abuse Git’s ext:: transport, and bypass the Docker sandbox’s directory‑block list, enabling remote code execution on the host from a single WhatsApp message. All three bugs were fixed in OpenClaw version 2026.6.6, and maintainers advise updating, disabling the exec tool for untrusted channels, enabling sandbox mode, and restricting DM pairing.

In the same release cycle, OpenClaw shipped a redesigned animated welcome screen, native Android image previews, and a series of UTF‑16 safety and CI stability fixes. The new UI aims to make the assistant feel more collaborative, while the Android preview brings mobile parity with the desktop experience. Users are encouraged to upgrade to benefit from both the security patches and the usability improvements.