OpenClaw has released version 2026.2.23, delivering major security improvements alongside new AI capabilities. The update patches multiple vulnerabilities, adds Claude Opus 4.6 support, and introduces optional HTTP security headers to reduce man-in-the-middle risks for local AI deployments on macOS, Windows, and Linux.
Session handling has been hardened with disk-budget controls, safer transcript storage, and stricter SSRF policies by default. Sensitive configuration data is now redacted, obfuscated commands require explicit approval, and tool permissions are tightly scoped to prevent unauthorized access. Additional protections block symlink escapes, XSS-prone prompts, and API key leaks in logs.
AI upgrades include Kilo Gateway integration, expanded Moonshot support (including video), improved caching controls, better context pruning, and enhanced failover handling. The release also stabilizes integrations for WhatsApp and Telegram, reinforcing OpenClaw’s position as a secure, multi-model AI platform.
















Comments