Executive brief
OpenClaw is a Discord-integrated personal assistant bot. A missing authorization check in the voice transcript handler allows non-owner participants in a shared Discord channel to access owner-only features (gateway and cron tools), potentially leading to unauthorized command execution or data access. The practical risk is limited to deployments with mixed-trust users sharing the same channel, which falls outside OpenClaw's recommended single-operator deployment model.
Technical details
OpenClaw's Discord voice transcript ingestion path calls agentCommand() without passing the senderIsOwner parameter. Due to a default behavior in agentCommand, when senderIsOwner is omitted, it defaults to true, incorrectly granting owner privileges to all voice transcript participants. The owner-only tool policy that restricts gateway and cron access is keyed on senderIsOwner, so the missing parameter allows non-owner voice participants to bypass this authorization check. The attack requires the attacker to join a voice channel where the OpenClaw bot is active and participate in a voice transcript session; no cross-gateway authentication bypass is required. This has been patched in version 2026.3.2 and later.
Affected products
- OpenClaw OpenClaw <= 2026.3.1
Timeline
- 2026-03-03: disclosed
- 2026-03-02: patched: Version 2026.3.2 released