GHSA-grc3-2j34-p6gmMedium▾ SunlitOpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
message.action forwarding could send Gateway credentials to model-supplied loopback URLs. In affected versions, model-controlled action metadata that selects a loopback Gateway URL could forward the action payload with Gateway credentials to the supplied loopback URL.
This advisory is scoped to the named feature and configuration. It does not change OpenClaw's trusted-operator model: authenticated Gateway operators, installed plugins, and intentional local execution surfaces remain trusted unless a separate policy, approval, allowlist, sandbox, or auth boundary is crossed.
When the affected feature is enabled and reachable, this could expose the token and action payload to a local listener chosen through the affected path. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path.
The first stable patched version is 2026.5.2.
restrict message action forwarding and avoid model-supplied loopback targets until patched. As general hardening, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when it is not needed.
openclaw <= 2026.4.29Upgrade to a patched release:
openclaw 2026.5.2Connected by shared product, vendor, weakness, or advisory.
GHSA-9c3v-684m-579cMedium· 6.5OpenClaw MCP SSE redirects could forward Authorization headers
GHSA-x7cf-6gp3-q5f8Medium· 7.1Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin
CVE-2026-35630High· 8.0OpenClaw: QQBot native approval buttons did not enforce configured approver identity
GHSA-c29c-2q9c-pc86HighOpenClaw: Slack allowFrom could bind to mutable display names
GHSA-qjpc-qf9m-xwmrHigh· 8.8OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
GHSA-gp79-m99v-gjmhMediumOpenClaw: Mattermost handlers could fall open when channel type was missing