Executive brief
OpenClaw is an automation and orchestration platform that handles sensitive approval workflows across messaging channels. A logic error in the approval authorization system could allow an unauthorized sender to bypass channel access controls and approve pending sensitive actions if they knew the approval ID, as long as no approver list was configured. This could lead to unauthorized command execution or sensitive operations being approved without proper authorization.
Technical details
The vulnerability is an authorization bypass in OpenClaw's approval system (CWE-862: Missing Authorization; CWE-183: Permissive List of Allowed Inputs). The root cause lies in the `createResolvedApproverActionAuthAdapter` function, which returned `{ authorized: true }` when the resolved approver list was empty. This was then interpreted as `explicit: true` authorization in `resolveApprovalCommandAuthorization`, which bypasses the normal channel sender authorization gate (`isAuthorizedSender`). An attacker with knowledge of a valid approval ID but without proper channel authorization could invoke `/approve <id>` to resolve pending `exec.approval.resolve` or `plugin.approval.resolve` actions when the helper-backed channel had no configured approvers. The fix (merged in PR #65714, version 2026.4.12 and later) tags empty-approver fallbacks as implicit (via a non-enumerable Symbol) rather than explicit, forcing `explicit: false` and re-enabling the normal sender authorization gate. Regression tests were added to prevent reintroduction of this vulnerability.
Affected products
- OpenClaw openclaw < 2026.4.12
Timeline
- 2026-04-17: disclosed
- 2026-04-13: patched: Fix merged in PR #65714
- 2026-04-17: advisory: GHSA-49cg-279w-m73x published
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-49cg-279w-m73x
- https://github.com/openclaw/openclaw/pull/65714
- https://github.com/openclaw/openclaw/commit/0a105c0900de701d2ee9f1abc96b017afbd0afdd
- https://github.com/openclaw/openclaw
- https://www.vulncheck.com/advisories/openclaw-improper-authorization-via-empty-approver-lists