Junglewise Threat Intelligence

OpenClaw commands.allowFrom authorization bypass via conversation identifiers

Severity: medium · CVSS 4 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI automation platform that executes commands and directives based on configured authorization rules. The commands.allowFrom feature restricts which users can execute specific commands. However, a flaw caused the authorization logic to incorrectly accept conversation identifiers (like Discord channels or WhatsApp groups) as valid sender identities, potentially allowing any participant in that conversation to execute restricted commands instead of only the intended individual user.

Technical details

The vulnerability is an authorization bypass (CWE-639) in OpenClaw's command authorization mechanism. The root cause lies in resolveSenderCandidates() in src/auto-reply/command-auth.ts, which unconditionally includes ctx.From as a sender candidate during commands.allowFrom authorization checks. The flaw exploits the dual nature of ctx.From: it represents individual sender identity in direct-message contexts but represents conversation identity (channels, groups, threads) in group/channel contexts. When operators configured commands.allowFrom with conversation-like identifiers (Discord channel:<id>, WhatsApp group JIDs with @g.us suffix), the authorization logic would incorrectly grant access to all conversation participants. The attack requires authentication (PR:L) and direct network access to invoke commands, but no user interaction is needed. An attacker with membership in a targeted conversation can exploit this to execute command-only or directive-only flows they should not have access to. The fix (released in version 2026.2.23) restricts commands.allowFrom to sender-only principals, explicitly blocking conversation-shaped ctx.From identifiers (channel:, group:, thread:, @g.us) while preserving fallback behavior for direct messages when sender fields are absent. Regression tests were added to prevent recurrence.

Affected products

  • OpenClaw openclaw <=2026.2.22-2

Timeline

  • 2026-02-24: disclosed: Vulnerability disclosed via GitHub Security Advisory
  • 2026-02-24: patched: Fix committed (08e2aa44e78a9c946d97bea62304e6f533b8fa8e); patched version 2026.2.23 released
  • 2026-03-03: advisory: Advisory published as GHSA-2ch6-x3g4-7759

References

Related threats