Executive brief
OpenClaw is a personal AI assistant platform. A security flaw in its BlueBubbles integration allows unauthorized participants to bypass sender restrictions by manipulating conversation identifiers. This could allow an attacker to receive automated responses or access data intended only for specific, trusted users.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in OpenClaw's BlueBubbles sender policy. The system matches allowlist entries against mutable conversation-level metadata rather than stable, immutable sender identities. A network-based attacker with low privileges who can influence conversation identifiers can bypass sender restrictions to receive agent responses. This issue is fixed in version 2026.5.7. Operators are advised to use stable identifiers and restrict BlueBubbles group access as a mitigation.
Affected products
- OpenClaw openclaw <= 2026.5.6
Timeline
- 2026-05-28: disclosed: Initial disclosure by reporter
- 2026-06-18: advisory: GitHub Advisory published
- 2026-05-28: patched: Version 2026.5.7 released