Executive brief
OpenClaw is a software gateway used for managing automated bot interactions. A vulnerability in the QQBot streaming command allows unauthorized users to modify the system's configuration without being on an approved list. This could allow an attacker to change how the bot operates or redirect data, potentially disrupting services or bypassing administrative policies.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in OpenClaw's QQBot streaming command. In affected versions, the system fails to enforce explicit non-wildcard allowlist entries for the 'allowFrom' configuration during command execution. This allows a network-based attacker to send commands that mutate the QQBot streaming configuration without proper authorization. The vulnerability is exploitable if the feature is enabled and reachable by lower-trust inputs. A fix is available in version 2026.4.29.
Affected products
- openclaw openclaw <= 2026.4.27
Timeline
- 2026-05-28: disclosed
- 2026-07-02: advisory
- 2026.4.29: patched