OpenClaw 2026.9.6 turns on Code Mode by default, and its default executor is not a sandbox
OpenClaw 2026.9.6, released on September 23, 2026, changes three things that existing installations will feel. Code Mode now switches on by itself for recommended models, and its default Node executor runs with the Gateway's own operating system privileges. Code Mode also stops accepting TypeScript. The macOS app of this release can crash on every launch, so Mac users are told not to update yet.
OpenClaw shipped version 2026.9.6 on September 23, 2026. The release notes run to several thousand lines, and most entries are interface work and fixes. A handful change how an existing installation behaves after the update, and one of them concerns what model-written code is allowed to do.
Mac users should wait
The GitHub release opens with a warning. The 2026.9.6 macOS app can crash on every launch after an in-app update. OpenClaw has pulled it from the Sparkle update feed, and a 2026.9.7 hotfix for the Mac is in progress. If the app no longer starts, the project says to reinstall the 2026.9.5 macOS build. The npm package and the Gateway at 2026.9.6 are not affected.
Code Mode switches on by itself
Code Mode lets a model write and run code cells that call tools. From this release it activates automatically for catalog-preferred models when the global setting is absent, including after an upgrade. An explicit false keeps it off. Haiku 4.5 is excluded from automatic selection.
The release notes state plainly that the default Node executor runs with the Gateway's operating system privileges and is not a security sandbox. For an isolated guest, you select quickjs through tools.codeMode.executor. The notes add that QuickJS isolation does not remove access to tools your tool policy already permits.
Code Mode now runs plain JavaScript only, which breaks existing TypeScript cells. They have to be rewritten without TypeScript syntax, and the language and typecheck arguments must go. openclaw doctor --fix removes the old tools.codeMode.languages setting, but no migration rewrites your code.
Approvals that no longer carry over
Three security entries change what runs without a person present.
- Substantively editing an automation retires its Always allow approval, even if the old contents are restored later. Older grants need one fresh approval after the upgrade, so unattended jobs may stop and wait.
- Standalone tool calls now follow the authenticated operator's agent and sandbox restrictions even when no saved session exists. Automation that relied on that exception may be refused.
- The shared Rust client of the Gateway moves to Rustls 0.23.45, which includes the fix for GHSA-2mjx-qc3c-rqvc.
New models
The release also adds chat support for Claude Opus 5.5, GPT-6 Sol and Luna, and Grok 4.7.
„runs with the Gateway’s operating-system privileges and is not a security sandbox“
Sources
Related

Claude Code mods are not sandboxed, and version 2.1.289 fixes a deny rule they could override
Anthropic introduced mods for Claude Code on October 1, 2026. They are TypeScript functions, shipped inside plugins, that can rewrite prompts, change tool calls, and redraw parts of the interface. The documentation says mods are not sandboxed and run with your permissions, which covers your files, environment variables, and API keys. On Team and Enterprise plans a built-in mod named sec-default loads first and restricts the mods that users install. Versions 2.1.288 and 2.1.289 fix several cases where permission rules did not hold.
Anthropicverified

GitHub Copilot retires four models and makes Balanced its default code review effort
GitHub deprecated four models across all Copilot experiences on October 2, 2026: Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7. On the same day it made Copilot code review available through the REST and GraphQL APIs. Balanced is now the default review effort level, a change that took effect on September 28, 2026. According to GitHub's documentation, a Balanced review consumes more AI credits than a Lite one.
GitHub Changelogverified

Apple will add controls to Full Disk Access on macOS, citing risks from AI agents
Apple said on October 2, 2026, that it will add controls to Full Disk Access, the macOS permission that lets an app read nearly everything on a Mac. The company says some developers use the permission in ways that expose files, mail, messages, and browsing history without users fully understanding it. Apple expects the risk to grow as AI agents become more capable and autonomous. The post gives no date, no macOS version, and no description of the new controls.
Appleverified