---
id: GHSA-hw9r-h9mr-4jff
title: >-
  OpenClaw: Scoped chat.send route inheritance could bypass admin command scope
  gates
summary: >-
  OpenClaw: Scoped chat.send route inheritance could bypass admin command scope
  gates
severity: high
cvss: 8.8
cwe:
  - CWE-862
  - CWE-863
vendor: openclaw
product: openclaw
ecosystem: npm
affected:
  - openclaw < 2026.5.18
patched:
  - openclaw 2026.5.18
published: '2026-07-02'
updated: '2026-07-02'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-hw9r-h9mr-4jff'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-hw9r-h9mr-4jff
  - url: 'https://github.com/advisories/GHSA-hw9r-h9mr-4jff'
tags:
  - ghsa
  - npm
ingestedAt: '2026-07-02T16:39:34.592Z'
---

## Overview

### Summary

Some internal command handlers require `operator.approvals` or `operator.admin` scopes. In affected releases, a scoped Gateway `chat.send` request delivered through an inherited external route could be evaluated as an external-channel command while still carrying the lower Gateway client scopes.

This issue affects scoped Gateway clients. It does not apply to shared-secret bearer HTTP compatibility endpoints, which are documented as full operator surfaces under OpenClaw's trust model.

### Affected configurations

This affects deployments where a scoped Gateway caller with `operator.write` can use `chat.send` with delivery into a session that has an inherited external delivery route.

### Impact

Commands that should have required `operator.approvals` or `operator.admin` could run with only `operator.write` in this routed context. Affected command families included approval resolution and selected administrative commands such as plugin, config, MCP, allowlist, and ACP mutations.

### Patched Versions

The first stable patched version is `2026.5.18`.

### Mitigations

Upgrade to `openclaw@2026.5.18` or later. Before upgrading, avoid granting `operator.write` tokens to clients that can deliver commands into sessions with external routes unless those clients are trusted with admin-like command effects.

## Affected packages

- `openclaw < 2026.5.18`

## Remediation

Upgrade to a patched release:

- `openclaw 2026.5.18`
