Executive brief
OpenClaw is an automation tool that uses Discord allowlists to control who can interact with it. The allowlist can be configured with user IDs or usernames. A vulnerability in how usernames are normalized (converted to a standard form) allows different usernames to collide to the same internal representation, potentially letting an attacker with a specially crafted username bypass authorization checks and gain unauthorized access to protected features.
Technical details
The vulnerability is an improper authentication flaw (CWE-287) in OpenClaw's Discord allowlist implementation. When administrators configure allowlists using Discord user names/tags rather than stable numeric user IDs, the system normalizes these names into "slugs" for matching. Due to flaws in slug normalization, different usernames can collide to the same slug value, allowing an attacker with a crafted username to match an allowlist entry they should not have access to. The attack requires network access and no user interaction or elevated privileges. The vulnerability affects all versions up to 2026.2.21-2 and is fixed in 2026.2.22 and later. The fix includes runtime canonicalization of resolved allowlist names to IDs without rewriting config files, and a new security audit command that warns administrators about the risks of name-based allowlists.
Affected products
- OpenClaw openclaw <=2026.2.21-2
Timeline
- 2026-03-03: disclosed: Advisory published
- 2026-02-22: patched: Fixed in version 2026.2.22