Executive brief
OpenClaw is a software package used for managing Model Context Protocol (MCP) operations. A security flaw in its loopback communication path allows a local user to spoof their identity by manipulating request headers. This could allow an unauthorized user to perform administrative or 'owner-only' actions, potentially leading to full system compromise or unauthorized data access.
Technical details
A vulnerability in the OpenClaw npm package (versions <= 2026.4.21) exists where the MCP loopback runtime derives the 'senderIsOwner' context from spoofable request headers rather than secure tokens. An attacker with local access can provide malicious metadata in request headers to impersonate the owner of the process. This allows the attacker to bypass access controls and execute operations restricted to the owner. The issue is fixed in version 2026.4.22 by implementing separate bearer tokens for owner and non-owner contexts and ignoring the untrusted headers.
Affected products
- OpenClaw openclaw <= 2026.4.21
Timeline
- 2026-04-23: disclosed: Advisory published by maintainers
- 2026-04-23: patched: Fix commit 3cb1a56 released in version 2026.4.22
- 2026-05-04: advisory: GitHub Advisory GHSA-r6xh-pqhr-v4xh published
References
- https://api.github.com/users/VladimirEliTokarev
- https://github.com/VladimirEliTokarev
- https://api.github.com/users/VladimirEliTokarev/gists%7B/gist_id%7D
- https://api.github.com/users/VladimirEliTokarev/repos
- https://avatars.githubusercontent.com/u/58337987?v=4
- https://api.github.com/users/VladimirEliTokarev/events%7B/privacy%7D