Executive brief
OpenClaw is an AI assistant platform. A security flaw in its gateway component allowed certain local network requests to bypass authentication checks. This could allow an unauthorized user on the same network or host to access internal communication channels and data without providing valid credentials.
Technical details
An authentication bypass vulnerability exists in OpenClaw's gateway server. The root cause is located in `src/gateway/server/http-auth.ts`, where the `authorizeCanvasRequest` function incorrectly treated `isLocalDirectRequest` as an unconditional allow path. This allowed loopback HTTP and WebSocket requests to bypass bearer token or capability-based authentication checks. An attacker capable of sending requests via the loopback interface could gain unauthorized access to Canvas and A2UI routes. The issue is fixed in version 2026.3.23 by removing the early return logic for local requests.
Affected products
- OpenClaw openclaw < 2026.3.23
Timeline
- 2026-03-24: disclosed
- 2026-03-24: patched
- 2026-03-26: advisory
References
- https://api.github.com/users/smaeljaish771
- https://github.com/smaeljaish771
- https://api.github.com/users/smaeljaish771/gists%7B/gist_id%7D
- https://api.github.com/users/smaeljaish771/repos
- https://avatars.githubusercontent.com/u/266604088?v=4
- https://api.github.com/users/smaeljaish771/events%7B/privacy%7D