Executive brief
OpenClaw is a tool that manages automated permissions and function calls in AI agent systems. The ACP client component incorrectly auto-approves certain operations based on untrustworthy metadata and naming patterns, allowing attackers to bypass security prompts that normally require manual approval. An attacker can exploit this by spoofing tool metadata to gain unauthorized access to operations they should not be able to perform.
Technical details
The vulnerability is an improper authorization bypass (CWE-285) in the OpenClaw ACP client's permission resolution logic. The client trusts untrusted toolCall.kind metadata and uses permissive name heuristics to auto-approve tool invocations for read-class operations, without proper scoping to allowed paths (cwd). Attackers can craft malicious or compromised tool invocations with spoofed kind metadata or non-core read-like names to reach auto-approval paths and bypass interactive approval prompts. The fix requires validating tool IDs against a trusted core list, ignoring toolCall.kind as an authorization source, enforcing stricter scope validation, and tightening tool-name validation. The vulnerability affects OpenClaw versions up to 2026.2.22-2, with patched code available in version 2026.2.23.
Affected products
- OpenClaw OpenClaw prior to 2026.2.23
Timeline
- 2026-02-24: disclosed: Advisory GHSA-7jx5-9fjg-hp4m published
- 2026-02-24: patched: Version 2026.2.23 released with fix
- 2026-03-21: other: Duplicate advisory GHSA-rcx4-77x4-hjx5 published
- 2026-03-24: other: Duplicate advisory GHSA-rcx4-77x4-hjx5 withdrawn