Executive brief
OpenClaw is an AI assistant platform. A security flaw in its gateway component allowed users with low-level 'write' permissions to perform administrative session resets, which should normally require full administrator access. This could allow an unauthorized operator to disrupt or reset active sessions, potentially impacting system integrity and operational control.
Technical details
A missing authorization check (CWE-862) exists in the OpenClaw gateway's agent RPC implementation. Specifically, the '/reset' and '/new' message paths in 'src/gateway/server-methods/agent.ts' reached the session reset logic without verifying the 'operator.admin' privilege. While the direct 'sessions.reset' RPC correctly enforced this guard, the agent-based path only required 'operator.write' permissions. An attacker with low-privileged network access could exploit this to reset gateway sessions by providing an explicit sessionKey. The vulnerability is fixed in version 2026.3.23 by adding the necessary admin-level checks.
Affected products
- OpenClaw openclaw < 2026.3.23
Timeline
- 2026-03-24: patched: Fix commit 50f6a2f136fed85b58548a38f7a3dbb98d2cd1a0 merged.
- 2026-03-26: advisory: GitHub Advisory GHSA-wq58-2pvg-5h4f published.
References
- https://api.github.com/users/smaeljaish771
- https://github.com/smaeljaish771
- https://api.github.com/users/smaeljaish771/gists%7B/gist_id%7D
- https://api.github.com/users/smaeljaish771/repos
- https://avatars.githubusercontent.com/u/266604088?v=4
- https://api.github.com/users/smaeljaish771/events%7B/privacy%7D