Executive brief
OpenClaw is an open-source orchestration platform that includes a QQBot messaging component. A vulnerability in the QQBot streaming command allows authenticated users to modify configuration settings without proper authorization checks, potentially enabling them to bypass administrative policies and alter system behavior outside intended parameters.
Technical details
The vulnerability is an authorization bypass (CWE-290) in the QQBot streaming command of OpenClaw versions prior to 2026.4.29. Authenticated senders can mutate QQBot streaming configuration without requiring explicit non-wildcard allowlist entries, bypassing intended access controls. The attack requires the affected feature to be enabled and reachable by the attacker. The vulnerability does not affect OpenClaw's trusted-operator model for authenticated Gateway operators, installed plugins, and intentional local execution surfaces. A patch is available in version 2026.4.29 or later. Mitigation options include disabling the command, restricting it to explicit trusted senders, and maintaining narrow channel/tool allowlists.
Affected products
- OpenClaw OpenClaw before 2026.4.29
Timeline
- 2026-05-28: disclosed
- 2026-04-29: patched: Patched in version 2026.4.29
- 2026-06-13: advisory: GHSA-r27j-fxmq-rg2q published (marked as duplicate of GHSA-jvm4-4j77-39p6)
- 2026-08-27: other: Advisory withdrawn as duplicate of GHSA-jvm4-4j77-39p6