OpenClaw releases beta version: Memory system supports multimodal indexing, fixes high-risk administrator privilege hijacking vulnerability

Gate News: On March 12, OpenClaw, an open-source AI intelligent platform, released version v2026.3.11-beta.1 on March 11, featuring 15 new functions and numerous security fixes. The memory system now supports multimodal indexing for the first time, allowing users to create searchable vector indexes for local images and audio files. It relies on Google’s Gemini embedding-2-preview model, supports custom output dimensions, and automatically triggers reindexing when dimensions change.

For local model experience, the new version adds a one-stop onboarding process for Ollama, supporting both “pure local” and “cloud + local” modes, with a built-in recommended model list. The iOS version introduces a welcome page with real-time intelligent agent status overview, replacing floating controls with a fixed bottom toolbar. The macOS version adds a chat model selector.

In terms of security, this release fixes a high-risk WebSocket hijacking vulnerability (GHSA-5wcw-8jjv-m286). In trusted-proxy mode, attackers can bypass browser origin verification to gain operator.admin administrator privileges. Additionally, multiple security issues have been addressed, including sandbox temporary file escape, session reset privilege escalation, unverified plugin route inheritance of admin rights, and sub-agent privilege escalation.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Trusta AI Completes LayerZero Multi-DVN Configuration Upgrade, TA Cross-Chain Functionality Fully Restored

Gate News message, April 26 — Trusta AI, an AI-powered trusted identity network, has announced the full restoration of its cross-chain functionality via LayerZero. The protocol had previously faced disruptions after LayerZero transitioned from a 1/1 DVN configuration to a multi-DVN redundancy

GateNews1h ago

Aave Proposes 25,000 ETH for Kelp DAO Exploit Relief Fund

Aave service providers put forth a governance proposal on Friday that would contribute 25,000 ETH worth nearly $58 million from the protocol's DAO to DeFi United, a coordinated relief effort to restore backing for rsETH following the Kelp DAO exploit. The proposed contribution aims to close the rema

CryptoFrontier8h ago

XRP Breakout Holds as XRPL Lending Vote Gains Momentum

Key Insights XRP maintains weekly strength above major cryptocurrencies as price holds above key EMAs, reflecting sustained momentum despite minor daily declines in trading sessions. XRPL validators advance lending upgrades through XLS-65 and XLS-66, introducing pooled liquidity vaults and f

CryptoNewsLand8h ago

XRP Breakout Holds as XRPL Lending Vote Gains Momentum

XRP shows weekly strength, trading above EMAs after breaking from a descending wedge; XRPL advances XLS-65/66 lending upgrades with pooled vaults and fixed-term loans; derivatives rise in volume, open interest, and options activity. Abstract: This report notes XRP's persistent weekly momentum and price strength above key moving averages following a breakout from a descending wedge. It covers XRPL validators voting on XLS-65 and XLS-66, enabling native lending, pooled liquidity vaults, and fixed-term loans to expand on-chain financial activity. It also reports rising derivatives participation, with higher trading volume, open interest, and a surge in options activity, suggesting increasing trader positioning for a continued breakout.

CryptoNewsLand8h ago

Charles Hoskinson Launches Midnight With $250M in Tokenized Deposits From Monument Bank

Gate News message, April 25 — Charles Hoskinson, founder of Cardano, has launched Midnight, a privacy-focused blockchain project, with approximately $250 million in tokenized deposits from Monument Bank. The partnership represents a significant institutional collaboration aimed at integrating blockc

GateNews12h ago

JPMorgan ETF Trend Report: API-ification, Active Management at 83%, Tokenization Split into Two Paths—Synthetic and Native

JPMorgan Chase’s report highlights three major trends: 1) AP’s API automated trading accounts for about 50% of top-tier market traffic; 2) in 2025, actively managed ETFs make up 83% of new issuance, and are expected to become mainstream in 2026–27; 3) tokenization splits into two paths: synthetic (mirroring prices through derivatives) and native (issued on the blockchain). The report emphasizes improving transparency and governance with tools such as Athena, and monitors subsequent follow-through and the timeline toward formal productization.

ChainNewsAbmedia12h ago
Comment
0/400
No comments