Executive brief
OpenClaw is an automation framework that integrates with messaging platforms like QQ. A security flaw in its QQBot component allows users to bypass administrative restrictions, potentially executing commands that should be limited to private messages or specific authorized senders. This could allow a user with basic access to perform unauthorized administrative actions, depending on how the bot is configured.
Technical details
A policy bypass vulnerability exists in OpenClaw's QQBot admin command implementation due to incorrect authorization checks (CWE-863). Specifically, the software fails to properly enforce 'DM-only' and 'allowFrom' policy restrictions when an authenticated sender triggers exported commands. This allows an attacker who can reach the command path to route administrative actions from unauthorized contexts or senders. The vulnerability is reachable over the network by authenticated users. A fix is available in version 2026.4.29, and users are advised to disable exported QQBot admin commands as a temporary mitigation.
Affected products
- OpenClaw OpenClaw < 2026.4.29
Timeline
- 2026-05-28: advisory: GitHub Security Advisory GHSA-w4v6-g3wm-w36c published
- 2026-05-29: disclosed: CVE-2026-34507 published
- 2026-04-29: patched: Version 2026.4.29 released