Junglewise Threat Intelligence

CVE-2026-41350: OpenClaw session_status authorization bypass in unsandboxed invocations

CVE-2026-41350 · Severity: medium · CVSS 4 · Published 2026-04-07

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a JavaScript library that manages tool invocations and session policies in agent applications. A flaw in the `session_status` tool allows it to bypass configured visibility restrictions when running outside of a sandbox, potentially exposing session information to callers who should not have access. This could enable unauthorized agents to read sensitive session data within the same system.

Technical details

The vulnerability is an authorization bypass (CWE-863) in which the `session_status` tool skips the configured `tools.sessions.visibility` access control guard when invoked without sandboxing. This is a same-agent session-policy bypass—an attacker with existing access to the system can invoke the tool unsandboxed to retrieve session data that should be restricted by policy. The flaw affects OpenClaw versions up to and including 2026.3.28; the fix is applied in version 2026.3.31 and later via commit 4d369a3, which hardens the visibility guard for all callers. No authentication is required because this represents a policy bypass within an already-compromised or misconfigured agent environment.

Affected products

  • OpenClaw OpenClaw <=2026.3.28

Timeline

  • 2026-04-07: disclosed: Advisory published
  • 2026-03-30: patched: Fix committed; fix released in version 2026.3.31

References

Related threats