⚠ Withdrawn by GitHub Security Advisories

Withdrawn: May 18, 2026

GHSA-m5j2-r859-r5cvMediumCVSS 5.3Disclosed before NVD

Duplicate Advisory: OpenClaw: Isolated cron awareness events were recorded as trusted system events

Published
May 11, 2026
Last Modified
May 18, 2026

📋 Description

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-57r2-h2wj-g887. This link is maintained to preserve external references. ### Original Description OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attackers can exploit this trust-labeling issue to strengthen prompt-injection attacks by rendering untrusted events as trusted System events.

🎯 Affected products1

  • npm/openclaw:< 2026.4.20

🔗 References (5)