Executive brief
OpenClaw Gateway is an AI task automation platform that manages user sessions and operational access through role-based scopes. A flaw in the HTTP-based session history endpoint allows authenticated users to retrieve session history without the proper "operator.read" permission, even though the same protection exists on the WebSocket interface. An attacker with a valid authentication token but limited permissions could access sensitive session data they are not authorized to view.
Technical details
The vulnerability is an authorization bypass (CWE-863, CWE-639) in the GET /sessions/:sessionKey/history HTTP route of OpenClaw Gateway. The endpoint authenticates bearer tokens via the authorizeHttpGatewayBearerRequestOrReply function but omits the operator.read scope validation that is enforced on the equivalent WebSocket chat.history route. An authenticated attacker can craft HTTP requests to the history endpoint and retrieve session transcripts without holding the required scope. The fix (commit 1c45123) adds scope validation by checking the x-openclaw-scopes header and rejecting requests missing operator.read. Exploitation requires valid bearer token authentication but no user interaction or additional preconditions beyond network access to the gateway.
Affected products
- OpenClaw openclaw <= 2026.3.24
Timeline
- 2026-03-29: disclosed
- 2026-03-26: patched: Commit 1c45123231516fa50f8cf8522ba5ff2fb2ca7aea
- 2026-03-29: advisory