Executive brief
OpenClaw is an AI platform that automates tasks across different systems. The vulnerability allows users with basic write permissions to the gateway to manipulate a "verbose mode" setting that should only be controllable by administrators. By exploiting this flaw, an attacker could expose detailed internal reasoning or tool output that administrators intended to keep hidden, potentially revealing sensitive operational details.
Technical details
The vulnerability is a broken access control flaw (CWE-284, CWE-863) in the gateway's directive handling. The chat.send endpoint accepts a /verbose parameter that allows callers with write scope to persist verbose output settings at the session level, even though the same operation through the sessions.patch endpoint correctly enforces admin-only restrictions. An attacker with write-scoped API credentials can invoke the chat.send endpoint with a /verbose parameter to persistently enable verbose mode, causing subsequent gateway operations to expose reasoning output and tool details that should be restricted. No user interaction or elevated authentication is required—only network access to the gateway and existing write-scoped credentials. The fix, released in version 2026.3.28 (commit c603123528), enforces admin-level permission checks on verbose persistence in the directive handling layer, blocking non-admin callers from persisting these settings regardless of entry point.
Affected products
- OpenClaw openclaw <= 2026.3.24
Timeline
- 2026-03-31: disclosed: Advisory GHSA-5h2w-qmfp-ggp6 published
- 2026-03-28: patched: Fixed in version 2026.3.28; patch released by commit c603123528
- 2026-03-27: other: Fix commit authored