Executive brief
OpenClaw is a messaging platform that uses display name-based policy controls to manage which contacts can receive responses from agents. A vulnerability allows contacts with mutable (changeable) display names to circumvent these controls by changing their display metadata, potentially receiving messages intended for different contacts. This could allow unauthorized access to agent responses when the feature is enabled.
Technical details
OpenClaw contains a policy enforcement vulnerability (CWE-290: Authentication Bypass by Spoofing) where Zalo contacts with mutable display metadata can match allowFrom policy entries by modifying their display names. The vulnerability exists in versions up to 2026.5.2 and affects the display name-based identity matching logic. An authenticated attacker with mutable display metadata can modify their display name to match a policy allowlist entry, bypassing the intended access controls. The vulnerability is only exploitable when the affected feature is enabled and reachable. OpenClaw patched the issue in version 2026.5.3; the recommended mitigation is to use stable Zalo identifiers instead of mutable display names for policy entries.
Affected products
- OpenClaw OpenClaw through 2026.5.2
Timeline
- 2026-05-28: disclosed
- 2026.5.3: patched: First stable patched version