---
id: GHSA-rggc-m335-3wvj
title: >-
  OpenClaw: Same-host trusted-proxy deployments could accept local forged
  identity headers
summary: >-
  OpenClaw: Same-host trusted-proxy deployments could accept local forged
  identity headers
severity: high
cwe:
  - CWE-269
  - CWE-284
  - CWE-287
  - CWE-290
  - CWE-863
vendor: openclaw
product: openclaw
ecosystem: npm
affected:
  - openclaw < 2026.5.18
patched:
  - openclaw 2026.5.18
published: '2026-07-02'
updated: '2026-07-02'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-rggc-m335-3wvj'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-rggc-m335-3wvj
  - url: 'https://github.com/advisories/GHSA-rggc-m335-3wvj'
tags:
  - ghsa
  - npm
ingestedAt: '2026-07-02T16:39:34.601Z'
---

## Overview

### Summary

Same-host trusted-proxy deployments could accept local forged identity headers. In affected versions, a local same-host caller that can reach the proxy-facing Gateway port could supply identity headers normally reserved for the trusted proxy.

This advisory is scoped to the named feature and configuration. It does not change OpenClaw's trusted-operator model: authenticated Gateway operators, installed plugins, and intentional local execution surfaces remain trusted unless a separate policy, approval, allowlist, sandbox, or auth boundary is crossed.

### Impact

When the affected feature is enabled and reachable, this could receive operator identity associated with the forged headers. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path.

### Patched Versions

The first stable patched version is `2026.5.18`.

### Mitigations

bind trusted-proxy ingress behind the actual proxy and firewall direct same-host access. As general hardening, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when it is not needed.

## Affected packages

- `openclaw < 2026.5.18`

## Remediation

Upgrade to a patched release:

- `openclaw 2026.5.18`
