Executive brief
OpenClaw is an open-source platform used for managing automated agents and gateways. A security flaw in its BlueBubbles integration allows unauthorized participants to trick the system into sending them messages or data intended for other users. This could lead to the exposure of sensitive agent responses to unauthorized parties if they can manipulate conversation metadata.
Technical details
A sender policy bypass vulnerability exists in OpenClaw's BlueBubbles integration due to the reliance on mutable conversation-level identifiers for authorization checks (CWE-807, CWE-863). In affected versions prior to 2026.5.7, an attacker with low privileges can influence conversation metadata to match entries in an allowlist. This allows the attacker to receive agent responses that were intended only for specific, configured senders. The attack requires the BlueBubbles feature to be enabled and reachable over the network, with a high complexity due to the need to manipulate specific conversation states. The issue is resolved in version 2026.5.7.
Affected products
- OpenClaw openclaw <= 2026.5.6
Timeline
- 2026-05-28: advisory: Original GHSA-8j37-5w68-wj2g published
- 2026-06-16: disclosed: NVD/CVE-2026-53860 published
- 2026-06-18: other: Duplicate advisory GHSA-8hj2-w4c9-fjfq withdrawn