Executive brief
OpenClaw is an AI automation platform that includes a Control UI for managing gateway connections. The vulnerability allows sessions connected through a trusted proxy without device identity verification to retain privileged scopes (admin or secrets access) that should only be granted to properly-authenticated devices. An attacker with network access to the trusted proxy could bypass device identity checks and gain unauthorized administrative or secrets access.
Technical details
The vulnerability is an authorization/privilege escalation flaw in the gateway WebSocket connection handling. Sessions originating from a trusted proxy without device identity could retain self-declared privileged scopes (admin or secrets) on the device-less allow path (handled in src/gateway/server/ws-connection/connect-policy.ts). The root cause is that scope validation was not properly stripping unbound self-declared scopes for device-less connections. An unauthenticated or minimally-authenticated attacker with network access to the trusted proxy can exploit this by crafting a WebSocket connection and self-declaring privileged scopes without presenting a valid device identity. The fix (commit ccf16cd) adds scope scrubbing in src/gateway/server/ws-connection/message-handler.ts to strip unbound self-declared scopes on the no-device path, preventing privilege retention without device identity. The patch shipped in version 2026.3.22 and later.
Affected products
- OpenClaw openclaw < 2026.3.22
Timeline
- 2026-03-26: disclosed: Advisory GHSA-48vw-m3qc-wr99 published
- 2026-03-17: patched: Fix committed (ccf16cd); released in v2026.3.22