Executive brief
OpenClaw's Canvas gateway component is responsible for routing HTTP and WebSocket requests to the application. Before version 2026.3.23, the gateway incorrectly allowed unauthenticated loopback requests to bypass security checks, enabling attackers to access protected Canvas routes without proper credentials. This could allow unauthorized access to sensitive operations and data.
Technical details
The vulnerability is an authentication bypass (CWE-288) in the authorizeCanvasRequest() function within src/gateway/server/http-auth.ts. The function unconditionally returned success for local-direct requests without validating bearer tokens or Canvas capabilities. Attackers on the local system could send unauthenticated HTTP and WebSocket requests to Canvas routes via loopback to bypass authentication. This required network access to the loopback interface (local attacker or compromised local process). The fix in version 2026.3.23 enforces authentication checks for all requests, including those from localhost.
Affected products
- OpenClaw OpenClaw < 2026.3.23
Timeline
- 2026-03-24: disclosed
- 2026-03-23: patched: Version 2026.3.23 and later include the fix
- 2026-04-10: advisory: GHSA-9gvx-vj57-vqqx published and subsequently withdrawn as duplicate of GHSA-6mqc-jqh6-x8fc