What happened
OpenClaw versions >=2026.4.5 and <2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory (GHSA-62qm-6fjj-6g23, CVSS 7.5). This is described as a new class of AI-specific privilege escalation: a low-privilege/restricted input becomes an authoritative instruction to an unattended privileged agent.
Why it matters
Represents a distinctive AI-specific privilege-escalation pattern — privilege/trust provenance is not carried through agent memory persistence, so content a restricted sender could never execute is later executed by a privileged background process. Defenders should enable requester-specific tool policies consistently across memory recall and dreaming paths, and upgrade to 2026.8.1+.
Attack vector
An attacker who can send a message to a restricted sender channel feeds crafted text into a session; because the persisted session memory strips the originating requester's tool restrictions, the background dreaming agent later acts on the embedded instructions with the agent's broader tool authority and the host's credentials.
Mitigation
Upgrade OpenClaw to 2026.8.1 or later; if unable, disable session-memory capture/dreaming. Advisory: https://github.com/openclaw/openclaw/security/advisories/GHSA-62qm-6fjj-6g23