You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Update docs for June-July 2026 OpenClaw developments
- Latest stable is now v2026.6.11 (June 30, 2026); v2026.7.1 in beta
(FAQ, security checklist, resources, quick-start banner)
- Document the June 30 batch of ~45 security advisories (MCP loopback,
plugin-install bypasses, model-override auth) patched in v2026.6.6-6.8,
plus v2026.6.11 DOMPurify and package-source hardening
- Add security cautions to MCP servers and plugin system guides
- Add recently-added model support table (Claude Fable 5, Kimi K2.7 Code,
GLM-5.2, Haiku 4.5, Gemini 3.5 Flash, GPT-5.6 beta, ClawRouter)
- Note Node 23 rejection coming in v2026.7.1; clarify calendar versioning
- Note Slack relay mode and channel reliability fixes in v2026.6.11
Sources verified against github.com/openclaw/openclaw changelog/releases/
advisories and docs.openclaw.ai as of 2026-07-08.
Copy file name to clipboardExpand all lines: docs/getting-started/installation.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,7 +11,7 @@ OpenClaw runs on **macOS**, **Linux**, and **Windows**. Choose the installation
11
11
12
12
## Prerequisites
13
13
14
-
-**Node.js 24** (recommended) or **Node.js 22 LTS** (22.19+ minimum)
14
+
-**Node.js 24** (recommended) or **Node.js 22 LTS** (22.19+ minimum). Node 23.11+ currently works, but avoid it — starting with v2026.7.1 the installer, CLI launcher, and `openclaw doctor` reject Node 23 and steer you to Node 22 or 24.
15
15
-**pnpm** (for git/developer installs — run `corepack enable` first)
16
16
- A supported LLM API key (Anthropic, OpenAI, OpenRouter, Google, xAI) *or* a local model setup
Copy file name to clipboardExpand all lines: docs/guides/mcp-servers.md
+4Lines changed: 4 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,6 +15,10 @@ As of mid-2026, the MCP ecosystem has **32,600+ servers** exposing **229,800+ to
15
15
MCP is the recommended integration path for most use cases. Before building a custom [plugin](/guides/plugin-system) or [skill](/guides/skill-development), check if an MCP server already exists for what you need.
16
16
:::
17
17
18
+
:::caution Security advisory
19
+
Versions v2026.5.20 through v2026.6.5 had a High-severity flaw ([GHSA-52xj-c9p8-78cv](https://github.com/openclaw/openclaw/security/advisories/GHSA-52xj-c9p8-78cv), CVSS 8.3) where the MCP loopback could expose owner-only tools to non-owner runs. Patched in v2026.6.6 — see the [June 2026 advisory batch](/security/known-vulnerabilities#june-2026-advisory-batch-june-30-2026).
Plugins extend OpenClaw at the gateway level. Where [skills](/guides/skill-development) teach agents new capabilities via Markdown, plugins add infrastructure — new channels, storage backends, orchestration layers, and monitoring hooks.
11
11
12
-
The plugin architecture matured significantly in **v2026.5.28–v2026.6.1** with externalized official plugins, a SQLite-backed install index, the SecretRef credential contract, and standardized lifecycle hooks.
12
+
The plugin architecture matured significantly in **v2026.5.28–v2026.6.1** with externalized official plugins, a SQLite-backed install index, the SecretRef credential contract, and standardized lifecycle hooks. **v2026.6.11** added plugin install/repair tooling; note that references to former root `skills/...` paths must now live inside the relevant plugin directory.
13
+
14
+
:::caution Security advisories
15
+
The [June 30, 2026 advisory batch](/security/known-vulnerabilities#june-2026-advisory-batch-june-30-2026) included two plugin-install flaws: [GHSA-7vrr-rp4x-4g76](https://github.com/openclaw/openclaw/security/advisories/GHSA-7vrr-rp4x-4g76) (High, CVSS 8.8 — install commands could allow non-owner persistence) and [GHSA-wgq8-x5wm-g4rw](https://github.com/openclaw/openclaw/security/advisories/GHSA-wgq8-x5wm-g4rw) (Moderate — install wrappers could skip install policy). Both are patched in current releases; run v2026.6.8 or later.
Copy file name to clipboardExpand all lines: docs/reference/faq.md
+2-1Lines changed: 2 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -39,7 +39,7 @@ Moltbook is a separate social network (created by Matt Schlicht) where AI agents
39
39
40
40
### What version is current?
41
41
42
-
As of June 2026, the latest stable release is **v2026.6.1** (published June 3, 2026). OpenClaw uses date-based versioning: `vYYYY.M.D`.
42
+
As of early July 2026, the latest stable release is **v2026.6.11** (published June 30, 2026), with **v2026.7.1** available as beta pre-releases. OpenClaw uses calendar versioning: `vYYYY.M.PATCH`, where the patch number is a sequential release counter within the month — not a calendar day.
43
43
44
44
---
45
45
@@ -49,6 +49,7 @@ As of June 2026, the latest stable release is **v2026.6.1** (published June 3, 2
49
49
50
50
OpenClaw is powerful but carries significant risks. It has had:
51
51
-**138+ CVEs** disclosed as of April 2026
52
+
-**~45 GitHub security advisories**[batch-published June 30, 2026](/security/known-vulnerabilities#june-2026-advisory-batch-june-30-2026) — mostly already patched in v2026.6.6–v2026.6.8
52
53
- A [critical RCE vulnerability](/security/known-vulnerabilities) (CVE-2026-25253)
53
54
-[4 chainable TOCTOU vulnerabilities](https://www.cyera.com/blog/claw-chain-cyera-research-unveil-four-chainable-vulnerabilities-in-openclaw) (Cyera Research, CVSS up to 9.6)
Copy file name to clipboardExpand all lines: docs/security/known-vulnerabilities.md
+35Lines changed: 35 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -70,6 +70,38 @@ openclaw --version
70
70
71
71
---
72
72
73
+
## June 2026 Advisory Batch (June 30, 2026)
74
+
75
+
On June 30, 2026, the OpenClaw project batch-published **~45 GitHub security advisories** (roughly 33 High and 12 Moderate severity). This was a coordinated disclosure of issues that had already been patched in the v2026.6.6–v2026.6.8 releases earlier in June — not a wave of new zero-days. If you are on **v2026.6.8 or later**, you are covered.
The full batch covers MCP loopback privilege exposure, plugin-install persistence and policy bypasses, and missing admin authorization on model overrides. Browse the complete list at [github.com/openclaw/openclaw/security/advisories](https://github.com/openclaw/openclaw/security/advisories).
87
+
88
+
### v2026.6.11 Security Hardening
89
+
90
+
The v2026.6.11 release (June 30, 2026) added two further security fixes:
91
+
92
+
-**Control UI DOMPurify update** ([GHSA-cmwh-pvxp-8882](https://github.com/advisories/GHSA-cmwh-pvxp-8882)) — the bundled sanitizer was updated to a patched DOMPurify release, mitigating `ALLOWED_ATTR` pollution via `setConfig()` (PR #95691)
93
+
-**Lookalike package-source rejection** — trusted OpenClaw package sources now reject lookalike sibling paths (e.g., trusting `/artifactory/openclaw` no longer admits `/artifactory/openclaw-malicious`)
94
+
95
+
### Mitigation
96
+
97
+
```bash
98
+
# Upgrade to v2026.6.8 or later (ideally the latest stable)
99
+
npm update -g openclaw
100
+
openclaw --version
101
+
```
102
+
103
+
---
104
+
73
105
## Gateway Authentication Bypass (JFrog)
74
106
75
107
JFrog published "[Giving OpenClaw the Keys to Your Kingdom](https://jfrog.com/blog/giving-openclaw-the-keys-to-your-kingdom-read-this-first/)" revealing that **93.4% of publicly reachable OpenClaw instances had critical authentication bypass vulnerabilities**.
@@ -374,6 +406,9 @@ When these findings were reported to creator Peter Steinberger, his response was
374
406
| Feb 9 | Follow-up: 135,000+ exposed instances, 42,665 on Shodan |**Critical**|
375
407
| Feb 9 | JFrog: 93.4% of exposed instances have auth bypass |**Critical**|
376
408
| Feb 9 | Gartner: "Unacceptable cybersecurity risk" published | — |
409
+
| Jun 12 | v2026.6.6 released — security-hardening release (140+ PRs) | Mitigation |
410
+
| Jun 30 |~45 security advisories batch-published (MCP loopback, plugin-install bypasses, model-override auth) — most patched in v2026.6.6–v2026.6.8 |**High**|
411
+
| Jun 30 | v2026.6.11 released — DOMPurify fix (GHSA-cmwh-pvxp-8882), lookalike package-source rejection | Mitigation |
Copy file name to clipboardExpand all lines: docs/security/overview.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -119,7 +119,7 @@ All of this abuses intended capabilities — no software vulnerability required.
119
119
120
120
For those who want to go deeper than the 5 quick steps:
121
121
122
-
-[ ]**Update to the latest stable release** (currently v2026.6.1) — patches critical RCE and many subsequent security improvements
122
+
-[ ]**Update to the latest stable release** (currently v2026.6.11) — patches critical RCE, the [June 30, 2026 advisory batch](/security/known-vulnerabilities#june-2026-advisory-batch-june-30-2026) (fixed in v2026.6.6–v2026.6.8), and many subsequent security improvements
123
123
-[ ]**Bind gateway to localhost** — never expose port 18789
124
124
-[ ]**Enable authentication** — token or password mode
125
125
-[ ]**Set `trustedProxies`** — if behind any reverse proxy
0 commit comments