Executive brief
BlueBubbles is a messaging feature in OpenClaw that enforces sender-based access controls. A participant who can influence conversation metadata can bypass these controls and match an allowlist entry intended for a different sender, potentially receiving agent responses they should not have access to. The practical impact depends on the operator's configuration and whether untrusted input can reach the affected feature.
Technical details
The vulnerability is an incorrect authorization (CWE-863) in OpenClaw's BlueBubbles sender policy enforcement. The vulnerable component uses mutable conversation-level identifiers (such as metadata) to match sender allowlist entries instead of relying on stable sender identity. An authenticated participant able to influence these conversation-level identifiers can forge a match and bypass sender policy controls. The attack requires the affected feature to be enabled and reachable. Patches are available in version 2026.5.7 and later.
Affected products
- OpenClaw openclaw <= 2026.5.6
Timeline
- 2026-05-28: disclosed
- 2026-05-28: patched: Version 2026.5.7 released
- 2026-06-16: other: Duplicate advisory published (GHSA-8hj2-w4c9-fjfq)
- 2026-06-18: other: Duplicate advisory withdrawn