The ACP bridge accepted very large prompt text blocks and could assemble oversized prompt payloads before forwarding them to chat.send.
Because ACP runs over local stdio, this mainly affects local ACP clients (for example IDE integrations) that send unusually large inputs.
openclaw (npm)<= 2026.2.172026.2.18 (planned next release)src/acp/event-mapper.tssrc/acp/translator.tschat.send732e53151e8fbdfc0501182ddb0e900878bdc1e3ebcf19746f5c500a41817e03abecadea8655654a63e39d7f57ac4ad4a5e38d17e7394ae7c4dd0b9cThanks @aether-ai-agent for reporting.
{
"severity": "MODERATE",
"cwe_ids": [
"CWE-400"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-20T21:52:44Z",
"nvd_published_at": null
}