Executive brief
OpenClaw Gateway is an AI automation platform that manages chat sessions and user interactions. A flaw in the chat messaging feature allowed users with write-level permissions to trigger admin-only session reset operations, potentially giving them unauthorized control over session lifecycles and archived transcript state without requiring admin credentials.
Technical details
This is an incorrect authorization / privilege escalation vulnerability in the chat.send endpoint (CWE-284, CWE-863). The affected components are src/gateway/server-methods/chat.ts and src/auto-reply/reply/session.ts. The root cause is that the `/reset` session rotation command reused general command authorization checks instead of enforcing admin-only scope, even though direct session reset is a control-plane operation restricted to administrators. A caller with `operator.write` scope can invoke `/reset` via chat.send to rotate sessions without admin privileges. The fix, released in version 2026.3.28 (commit be00fcfccba), aligns the authorization scope checks for chat.send reset operations with admin-level requirements.
Affected products
- OpenClaw openclaw <= 2026.3.24
Timeline
- 2026-04-01: disclosed
- 2026-03-28: patched: Fixed in version 2026.3.28