CVE-2026-27007 | OpenClaw/Clawdbot/Moltbot up to 2026.2.14 Configuration config-hash.ts normalizeForHash incorrect comparison logic granularity (WID-SEC-2026-0459)
A vulnerability marked as problematic has been reported in OpenClaw, Clawdbot and Moltbot up to 2026.2.14. This impacts the function normalizeForHash of the file src/agents/sandbox/config-hash.ts of the component Configuration Handler. The manipulation leads to incorrect comparison logic granularity.
This vulnerability is referenced as CVE-2026-27007. The attack can only be performed from a local environment. No exploit is available.
It is suggested to upgrade the affected component.