Skip to content
Agentsmedium signalverified

OpenClaw 2026.9.6 turns on Code Mode by default, and its default executor is not a sandbox

OpenClaw 2026.9.6, released on September 23, 2026, changes three things that existing installations will feel. Code Mode now switches on by itself for recommended models, and its default Node executor runs with the Gateway's own operating system privileges. Code Mode also stops accepting TypeScript. The macOS app of this release can crash on every launch, so Mac users are told not to update yet.

By Redakcija WebAiRadarPublished 2 min readwritten by a model

Source

openclaw 2026.9.6

OpenClaw · Original published September 23, 2026

OpenClaw shipped version 2026.9.6 on September 23, 2026. The release notes run to several thousand lines, and most entries are interface work and fixes. A handful change how an existing installation behaves after the update, and one of them concerns what model-written code is allowed to do.

Mac users should wait

The GitHub release opens with a warning. The 2026.9.6 macOS app can crash on every launch after an in-app update. OpenClaw has pulled it from the Sparkle update feed, and a 2026.9.7 hotfix for the Mac is in progress. If the app no longer starts, the project says to reinstall the 2026.9.5 macOS build. The npm package and the Gateway at 2026.9.6 are not affected.

Code Mode switches on by itself

Code Mode lets a model write and run code cells that call tools. From this release it activates automatically for catalog-preferred models when the global setting is absent, including after an upgrade. An explicit false keeps it off. Haiku 4.5 is excluded from automatic selection.

The release notes state plainly that the default Node executor runs with the Gateway's operating system privileges and is not a security sandbox. For an isolated guest, you select quickjs through tools.codeMode.executor. The notes add that QuickJS isolation does not remove access to tools your tool policy already permits.

Code Mode now runs plain JavaScript only, which breaks existing TypeScript cells. They have to be rewritten without TypeScript syntax, and the language and typecheck arguments must go. openclaw doctor --fix removes the old tools.codeMode.languages setting, but no migration rewrites your code.

Approvals that no longer carry over

Three security entries change what runs without a person present.

  • Substantively editing an automation retires its Always allow approval, even if the old contents are restored later. Older grants need one fresh approval after the upgrade, so unattended jobs may stop and wait.
  • Standalone tool calls now follow the authenticated operator's agent and sandbox restrictions even when no saved session exists. Automation that relied on that exception may be refused.
  • The shared Rust client of the Gateway moves to Rustls 0.23.45, which includes the fix for GHSA-2mjx-qc3c-rqvc.

New models

The release also adds chat support for Claude Opus 5.5, GPT-6 Sol and Luna, and Grok 4.7.

„runs with the Gateway’s operating-system privileges and is not a security sandbox“
OpenClaw 2026.9.6 release notes, on the default Node executor

Sources

Related

Anthropic's illustration for the mods announcement: a hand-drawn hand placing a white block onto a wall of outlined bricks, on an orange background.
Agentsstrong signal

Claude Code mods are not sandboxed, and version 2.1.289 fixes a deny rule they could override

Anthropic introduced mods for Claude Code on October 1, 2026. They are TypeScript functions, shipped inside plugins, that can rewrite prompts, change tool calls, and redraw parts of the interface. The documentation says mods are not sandboxed and run with your permissions, which covers your files, environment variables, and API keys. On Team and Enterprise plans a built-in mod named sec-default loads first and restricts the mods that users install. Versions 2.1.288 and 2.1.289 fix several cases where permission rules did not hold.

Anthropicverified

GitHub's screenshot of the review effort level menu: Organization default (Balanced) is selected, followed by Lite, Balanced, and Max marked Coming soon.
Agentsmedium signal

GitHub Copilot retires four models and makes Balanced its default code review effort

GitHub deprecated four models across all Copilot experiences on October 2, 2026: Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7. On the same day it made Copilot code review available through the REST and GraphQL APIs. Balanced is now the default review effort level, a change that took effect on September 28, 2026. According to GitHub's documentation, a Balanced review consumes more AI credits than a Lite one.

GitHub Changelogverified

Apple's illustration for its notice on Full Disk Access: a white disk drive symbol on a gray rounded square, set on a light gray background.
Agentsmedium signal

Apple will add controls to Full Disk Access on macOS, citing risks from AI agents

Apple said on October 2, 2026, that it will add controls to Full Disk Access, the macOS permission that lets an app read nearly everything on a Mac. The company says some developers use the permission in ways that expose files, mail, messages, and browsing history without users fully understanding it. Apple expects the risk to grow as AI agents become more capable and autonomous. The post gives no date, no macOS version, and no description of the new controls.

Appleverified