{"id":"GHSA-hw9r-h9mr-4jff","title":"OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates","summary":"OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates","severity":"high","cvss":8.8,"cwe":["CWE-862","CWE-863"],"vendor":"openclaw","product":"openclaw","ecosystem":"npm","affected":["openclaw < 2026.5.18"],"patched":["openclaw 2026.5.18"],"published":"2026-07-02","updated":"2026-07-02","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-hw9r-h9mr-4jff","references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-hw9r-h9mr-4jff"},{"url":"https://github.com/advisories/GHSA-hw9r-h9mr-4jff"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-02T16:39:34.592Z","slug":"GHSA-hw9r-h9mr-4jff","body":"## Overview\n\n### Summary\n\nSome internal command handlers require `operator.approvals` or `operator.admin` scopes. In affected releases, a scoped Gateway `chat.send` request delivered through an inherited external route could be evaluated as an external-channel command while still carrying the lower Gateway client scopes.\n\nThis issue affects scoped Gateway clients. It does not apply to shared-secret bearer HTTP compatibility endpoints, which are documented as full operator surfaces under OpenClaw's trust model.\n\n### Affected configurations\n\nThis affects deployments where a scoped Gateway caller with `operator.write` can use `chat.send` with delivery into a session that has an inherited external delivery route.\n\n### Impact\n\nCommands that should have required `operator.approvals` or `operator.admin` could run with only `operator.write` in this routed context. Affected command families included approval resolution and selected administrative commands such as plugin, config, MCP, allowlist, and ACP mutations.\n\n### Patched Versions\n\nThe first stable patched version is `2026.5.18`.\n\n### Mitigations\n\nUpgrade to `openclaw@2026.5.18` or later. Before upgrading, avoid granting `operator.write` tokens to clients that can deliver commands into sessions with external routes unless those clients are trusted with admin-like command effects.\n\n## Affected packages\n\n- `openclaw < 2026.5.18`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `openclaw 2026.5.18`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}