Skip to content

Commit 32ded73

Browse files
Update docs for June-July 2026 OpenClaw developments
- Latest stable is now v2026.6.11 (June 30, 2026); v2026.7.1 in beta (FAQ, security checklist, resources, quick-start banner) - Document the June 30 batch of ~45 security advisories (MCP loopback, plugin-install bypasses, model-override auth) patched in v2026.6.6-6.8, plus v2026.6.11 DOMPurify and package-source hardening - Add security cautions to MCP servers and plugin system guides - Add recently-added model support table (Claude Fable 5, Kimi K2.7 Code, GLM-5.2, Haiku 4.5, Gemini 3.5 Flash, GPT-5.6 beta, ClawRouter) - Note Node 23 rejection coming in v2026.7.1; clarify calendar versioning - Note Slack relay mode and channel reliability fixes in v2026.6.11 Sources verified against github.com/openclaw/openclaw changelog/releases/ advisories and docs.openclaw.ai as of 2026-07-08.
1 parent e48de86 commit 32ded73

10 files changed

Lines changed: 68 additions & 6 deletions

File tree

‎docs/getting-started/installation.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ OpenClaw runs on **macOS**, **Linux**, and **Windows**. Choose the installation
1111

1212
## Prerequisites
1313

14-
- **Node.js 24** (recommended) or **Node.js 22 LTS** (22.19+ minimum)
14+
- **Node.js 24** (recommended) or **Node.js 22 LTS** (22.19+ minimum). Node 23.11+ currently works, but avoid it — starting with v2026.7.1 the installer, CLI launcher, and `openclaw doctor` reject Node 23 and steer you to Node 22 or 24.
1515
- **pnpm** (for git/developer installs — run `corepack enable` first)
1616
- A supported LLM API key (Anthropic, OpenAI, OpenRouter, Google, xAI) *or* a local model setup
1717

‎docs/getting-started/quick-start.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -82,7 +82,7 @@ openclaw gateway
8282
You should see:
8383

8484
```
85-
🦞 OpenClaw Gateway v2026.6.1
85+
🦞 OpenClaw Gateway v2026.6.11
8686
WebSocket control plane: ws://localhost:18789
8787
Heartbeat interval: 30m
8888
Model: claude-sonnet-4-6

‎docs/guides/channels.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -303,6 +303,10 @@ openclaw channel add slack
303303
# ✓ Slack connected via Socket Mode
304304
```
305305

306+
:::info
307+
**v2026.6.11** added a Slack **relay mode**, alongside a batch of channel-reliability fixes (misplaced replies, stuck sends, reconnects) covering Google Chat DM routing, Discord/Telegram reply threading, Feishu voice replies, and iMessage turn consolidation.
308+
:::
309+
306310
### Configuration
307311

308312
```json5 title="~/.openclaw/openclaw.json"

‎docs/guides/mcp-servers.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,10 @@ As of mid-2026, the MCP ecosystem has **32,600+ servers** exposing **229,800+ to
1515
MCP is the recommended integration path for most use cases. Before building a custom [plugin](/guides/plugin-system) or [skill](/guides/skill-development), check if an MCP server already exists for what you need.
1616
:::
1717

18+
:::caution Security advisory
19+
Versions v2026.5.20 through v2026.6.5 had a High-severity flaw ([GHSA-52xj-c9p8-78cv](https://github.com/openclaw/openclaw/security/advisories/GHSA-52xj-c9p8-78cv), CVSS 8.3) where the MCP loopback could expose owner-only tools to non-owner runs. Patched in v2026.6.6 — see the [June 2026 advisory batch](/security/known-vulnerabilities#june-2026-advisory-batch-june-30-2026).
20+
:::
21+
1822
---
1923

2024
## What MCP Provides

‎docs/guides/model-selection.md‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,20 @@ OpenClaw is model-agnostic — it works with 30+ bundled provider plugins coveri
2828

2929
---
3030

31+
## Recently Added Model Support (June–July 2026)
32+
33+
Model catalog additions in recent releases, per the [official changelog](https://github.com/openclaw/openclaw/blob/main/CHANGELOG.md):
34+
35+
| Version | What was added |
36+
|---------|----------------|
37+
| **v2026.6.6** | Claude Fable 5 (adaptive thinking); OpenRouter OAuth onboarding |
38+
| **v2026.6.7** | Kimi K2.7 Code |
39+
| **v2026.6.8** | GLM-5.2 and Claude Haiku 4.5 catalog entries, with normalized provider-qualified IDs across OpenRouter and Google Vertex |
40+
| **v2026.6.11** | Gemini 3.5 Flash (full 1,048,576-token context); Ollama Cloud `glm-5.2:cloud` (1M context, reasoning, tools); Xiaomi Token Plan `mimo-v2.5` / `mimo-v2.5-pro` (up to 128K output tokens); fix for OpenRouter short DeepSeek V4 model IDs (`model_not_found` from a duplicated provider prefix) |
41+
| **v2026.7.1** (beta) | OpenAI GPT-5.6 model family; bundled ClawRouter provider plugin (credential-scoped dynamic model discovery, OpenAI-compatible plus native Anthropic/Gemini transports, budget reporting); Ollama inference-node auto-discovery |
42+
43+
---
44+
3145
## By Use Case
3246

3347
### Heartbeat (runs every 30 min — cost adds up)

‎docs/guides/plugin-system.md‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,11 @@ keywords: [openclaw, plugins, gateway plugin, extend openclaw, plugin developmen
99

1010
Plugins extend OpenClaw at the gateway level. Where [skills](/guides/skill-development) teach agents new capabilities via Markdown, plugins add infrastructure — new channels, storage backends, orchestration layers, and monitoring hooks.
1111

12-
The plugin architecture matured significantly in **v2026.5.28–v2026.6.1** with externalized official plugins, a SQLite-backed install index, the SecretRef credential contract, and standardized lifecycle hooks.
12+
The plugin architecture matured significantly in **v2026.5.28–v2026.6.1** with externalized official plugins, a SQLite-backed install index, the SecretRef credential contract, and standardized lifecycle hooks. **v2026.6.11** added plugin install/repair tooling; note that references to former root `skills/...` paths must now live inside the relevant plugin directory.
13+
14+
:::caution Security advisories
15+
The [June 30, 2026 advisory batch](/security/known-vulnerabilities#june-2026-advisory-batch-june-30-2026) included two plugin-install flaws: [GHSA-7vrr-rp4x-4g76](https://github.com/openclaw/openclaw/security/advisories/GHSA-7vrr-rp4x-4g76) (High, CVSS 8.8 — install commands could allow non-owner persistence) and [GHSA-wgq8-x5wm-g4rw](https://github.com/openclaw/openclaw/security/advisories/GHSA-wgq8-x5wm-g4rw) (Moderate — install wrappers could skip install policy). Both are patched in current releases; run v2026.6.8 or later.
16+
:::
1317

1418
---
1519

‎docs/reference/faq.md‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ Moltbook is a separate social network (created by Matt Schlicht) where AI agents
3939

4040
### What version is current?
4141

42-
As of June 2026, the latest stable release is **v2026.6.1** (published June 3, 2026). OpenClaw uses date-based versioning: `vYYYY.M.D`.
42+
As of early July 2026, the latest stable release is **v2026.6.11** (published June 30, 2026), with **v2026.7.1** available as beta pre-releases. OpenClaw uses calendar versioning: `vYYYY.M.PATCH`, where the patch number is a sequential release counter within the month — not a calendar day.
4343

4444
---
4545

@@ -49,6 +49,7 @@ As of June 2026, the latest stable release is **v2026.6.1** (published June 3, 2
4949

5050
OpenClaw is powerful but carries significant risks. It has had:
5151
- **138+ CVEs** disclosed as of April 2026
52+
- **~45 GitHub security advisories** [batch-published June 30, 2026](/security/known-vulnerabilities#june-2026-advisory-batch-june-30-2026) — mostly already patched in v2026.6.6–v2026.6.8
5253
- A [critical RCE vulnerability](/security/known-vulnerabilities) (CVE-2026-25253)
5354
- [4 chainable TOCTOU vulnerabilities](https://www.cyera.com/blog/claw-chain-cyera-research-unveil-four-chainable-vulnerabilities-in-openclaw) (Cyera Research, CVSS up to 9.6)
5455
- [341 malicious marketplace skills](/security/known-vulnerabilities#malicious-clawhub-skills-february-2026)

‎docs/reference/resources.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ For community-built tools, projects, and alternatives, see the [Ecosystem & Comm
2121
| **GitHub** | [github.com/openclaw/openclaw](https://github.com/openclaw/openclaw) | Source code (377k+ stars, 79k forks) |
2222
| **Documentation** | [docs.openclaw.ai](https://docs.openclaw.ai) | Official docs |
2323
| **ClawHub** | [github.com/openclaw/clawhub](https://github.com/openclaw/clawhub) | Skill marketplace (8,900 stars, 10,700+ skills) |
24-
| **Releases** | [GitHub Releases](https://github.com/openclaw/openclaw/releases) | Changelog, downloads (latest: v2026.6.1) |
24+
| **Releases** | [GitHub Releases](https://github.com/openclaw/openclaw/releases) | Changelog, downloads (latest stable: v2026.6.11) |
2525
| **Issues** | [GitHub Issues](https://github.com/openclaw/openclaw/issues) | Bug reports, feature requests (7,900+ open) |
2626
| **Security** | [Security Advisories](https://github.com/openclaw/openclaw/security/advisories) | Vulnerability reports, CVEs |
2727
| **Lobster** | [github.com/openclaw/lobster](https://github.com/openclaw/lobster) | Official workflow shell (440 stars) |

‎docs/security/known-vulnerabilities.md‎

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -70,6 +70,38 @@ openclaw --version
7070

7171
---
7272

73+
## June 2026 Advisory Batch (June 30, 2026)
74+
75+
On June 30, 2026, the OpenClaw project batch-published **~45 GitHub security advisories** (roughly 33 High and 12 Moderate severity). This was a coordinated disclosure of issues that had already been patched in the v2026.6.6–v2026.6.8 releases earlier in June — not a wave of new zero-days. If you are on **v2026.6.8 or later**, you are covered.
76+
77+
### Notable Advisories
78+
79+
| Advisory | Issue | CVSS | Affected | Fixed In |
80+
|----------|-------|------|----------|----------|
81+
| [GHSA-7vrr-rp4x-4g76](https://github.com/openclaw/openclaw/security/advisories/GHSA-7vrr-rp4x-4g76) | Plugin install commands could allow non-owner persistence | 8.8 (High) | — | v2026.6.6–6.8 window |
82+
| [GHSA-52xj-c9p8-78cv](https://github.com/openclaw/openclaw/security/advisories/GHSA-52xj-c9p8-78cv) | MCP loopback could expose owner-only tools to non-owner runs | 8.3 (High) | v2026.5.20 – < v2026.6.6 | v2026.6.6 |
83+
| [GHSA-jhfx-v2j8-x3m6](https://github.com/openclaw/openclaw/security/advisories/GHSA-jhfx-v2j8-x3m6) | OpenAI-compatible HTTP model overrides could miss admin authorization | 7.6 (High) | ≤ v2026.6.6 | v2026.6.8 |
84+
| [GHSA-wgq8-x5wm-g4rw](https://github.com/openclaw/openclaw/security/advisories/GHSA-wgq8-x5wm-g4rw) | Plugin install wrappers could skip install policy | Moderate | — | v2026.6.6–6.8 window |
85+
86+
The full batch covers MCP loopback privilege exposure, plugin-install persistence and policy bypasses, and missing admin authorization on model overrides. Browse the complete list at [github.com/openclaw/openclaw/security/advisories](https://github.com/openclaw/openclaw/security/advisories).
87+
88+
### v2026.6.11 Security Hardening
89+
90+
The v2026.6.11 release (June 30, 2026) added two further security fixes:
91+
92+
- **Control UI DOMPurify update** ([GHSA-cmwh-pvxp-8882](https://github.com/advisories/GHSA-cmwh-pvxp-8882)) — the bundled sanitizer was updated to a patched DOMPurify release, mitigating `ALLOWED_ATTR` pollution via `setConfig()` (PR #95691)
93+
- **Lookalike package-source rejection** — trusted OpenClaw package sources now reject lookalike sibling paths (e.g., trusting `/artifactory/openclaw` no longer admits `/artifactory/openclaw-malicious`)
94+
95+
### Mitigation
96+
97+
```bash
98+
# Upgrade to v2026.6.8 or later (ideally the latest stable)
99+
npm update -g openclaw
100+
openclaw --version
101+
```
102+
103+
---
104+
73105
## Gateway Authentication Bypass (JFrog)
74106

75107
JFrog published "[Giving OpenClaw the Keys to Your Kingdom](https://jfrog.com/blog/giving-openclaw-the-keys-to-your-kingdom-read-this-first/)" revealing that **93.4% of publicly reachable OpenClaw instances had critical authentication bypass vulnerabilities**.
@@ -374,6 +406,9 @@ When these findings were reported to creator Peter Steinberger, his response was
374406
| Feb 9 | Follow-up: 135,000+ exposed instances, 42,665 on Shodan | **Critical** |
375407
| Feb 9 | JFrog: 93.4% of exposed instances have auth bypass | **Critical** |
376408
| Feb 9 | Gartner: "Unacceptable cybersecurity risk" published | — |
409+
| Jun 12 | v2026.6.6 released — security-hardening release (140+ PRs) | Mitigation |
410+
| Jun 30 | ~45 security advisories batch-published (MCP loopback, plugin-install bypasses, model-override auth) — most patched in v2026.6.6–v2026.6.8 | **High** |
411+
| Jun 30 | v2026.6.11 released — DOMPurify fix (GHSA-cmwh-pvxp-8882), lookalike package-source rejection | Mitigation |
377412

378413
---
379414

‎docs/security/overview.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -119,7 +119,7 @@ All of this abuses intended capabilities — no software vulnerability required.
119119

120120
For those who want to go deeper than the 5 quick steps:
121121

122-
- [ ] **Update to the latest stable release** (currently v2026.6.1) — patches critical RCE and many subsequent security improvements
122+
- [ ] **Update to the latest stable release** (currently v2026.6.11) — patches critical RCE, the [June 30, 2026 advisory batch](/security/known-vulnerabilities#june-2026-advisory-batch-june-30-2026) (fixed in v2026.6.6–v2026.6.8), and many subsequent security improvements
123123
- [ ] **Bind gateway to localhost** — never expose port 18789
124124
- [ ] **Enable authentication** — token or password mode
125125
- [ ] **Set `trustedProxies`** — if behind any reverse proxy

0 commit comments

Comments
 (0)