Junglewise Threat Intelligence

OpenClaw MCP loopback authentication bypass via bearer token spoofing

Severity: low · CVSS 3.1 · Published 2026-05-06

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an open-source framework that allows plugins and child processes to communicate with a central gateway via a loopback interface. Prior to version 2026.4.22, the system incorrectly trusted authentication information provided in request headers rather than deriving it from the actual authentication token used. This allows a non-privileged loopback client to forge authentication headers and gain owner-level access to restricted operations, potentially exposing administrative functionality and sensitive data.

Technical details

The vulnerability is an authentication bypass (CWE-290) in OpenClaw's MCP (Model Context Protocol) loopback gateway. The root cause is that the gateway derives the "senderIsOwner" authorization context from a caller-controlled HTTP header (sender-owner) rather than from the cryptographically-validated bearer token used to authenticate the request. A non-owner loopback client can manipulate this header to present itself as an owner and gain unauthorized access to owner-gated operations. The attack requires local access (the attacker must be a loopback process) and does not require interaction. The fix, applied in version 2026.4.22, issues distinct bearer tokens for owner and non-owner contexts and derives authorization exclusively from which token class authenticated the request, eliminating reliance on spoofable headers.

Affected products

  • OpenClaw OpenClaw <= 2026.4.21

Timeline

  • 2026-05-06: disclosed: Advisory published (GHSA-35vf-vw9f-q3cr, duplicate of GHSA-r6xh-pqhr-v4xh)
  • 2026-04-21: patched: Fix commit 3cb1a56 authored
  • 2026-04-22: patched: Version 2026.4.22 released with patch
  • 2026-05-11: other: Original advisory GHSA-35vf-vw9f-q3cr withdrawn as duplicate

References

Related threats