mediumVulnerability

GHSA-2hm8-rqrm-xfjq

## Summary In authenticated non-owner DM sessions, a narrow tool-invocation path could reach broader-than-intended owner-only gateway actions. ## Impact This requires an authenticated non-owner sender in a DM session and a specific tool invocation path. No unauthenticated access is involved, and this does not provide direct code execution by itself. ## Root Cause - Some gateway call paths were still using broader default scopes instead of method-level least-privilege scopes. - Owner-only enforcement depended on tool-name checks and was not consistently metadata-driven across all call paths. ## Affected Packages / Versions - Package: `openclaw` (npm) - Affected: `<= 2026.2.17` (latest published npm version as of February 19, 2026) - Patched: `2026.2.19` ## Remediation - Refactored gateway method scope mapping to a data-driven table and added guard tests to ensure all exposed core gateway methods stay classified. - Centralized owner-only enforcement in tool policy wrappers and tool metadata. - Marked owner-only tools explicitly (`cron`, `gateway`, `whatsapp_login`) and removed duplicated per-tool owner checks. - Refactored gateway call path internals into smaller helpers while preserving behavior and coverage. ## Fix Commit(s) - `a40c10d3e24568b1e2947c104484be74bf66b8d2` - `2777d8ad91ef1e8a7c6f5b4b18f8507be7d02914` - `3d7ad1cfca4daaa84cd553e843e0e08fa6201349` OpenClaw thanks @Adam55A-code for reporting.

Properties

ghsa_id
GHSA-2hm8-rqrm-xfjq
severity
medium
summary
OpenClaw's owner-only gateway tool access checks were incomplete in specific authenticated DM flows
cve_id
GHSA-2hm8-rqrm-xfjq
is_ghsa_only
true
ghsa_published
2026-03-03T21:36:33Z
source_url
https://github.com/advisories/GHSA-2hm8-rqrm-xfjq
ghsa_updated
2026-03-03T21:36:34Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Improper Privilege Management
[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-2hm8-rqrm-xfjq — Ninja Signal Threat Intelligence | Ninja Signal