highVulnerability

GHSA-5h2w-qmfp-ggp6

## Summary The `chat.send` path let authorized write-scoped callers persist `/verbose` session overrides even though the same stored session mutation is admin-only through `sessions.patch`. ## Impact A write-scoped gateway caller could persist verbose output for later runs and expose more reasoning or tool output than the operator intended. ## Affected Component `src/auto-reply/reply/directive-handling.impl.ts, src/gateway/sessions-patch.ts` ## Fixed Versions - Affected: `<= 2026.3.24` - Patched: `>= 2026.3.28` - Latest stable `2026.3.28` contains the fix. ## Fix Fixed by commit `c603123528` (`fix(gateway): require admin for persisted verbose defaults`).

Properties

ghsa_id
GHSA-5h2w-qmfp-ggp6
summary
OpenClaw: Gateway `operator.write` can reach admin-only persisted `verboseLevel` via `chat.send` `/verbose`
severity
high
cve_id
GHSA-5h2w-qmfp-ggp6
is_ghsa_only
true
ghsa_published
2026-03-31T23:57:34Z
source_url
https://github.com/advisories/GHSA-5h2w-qmfp-ggp6
ghsa_updated
2026-03-31T23:57:35Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

REPORTED_BY (1)

[Source]GitHub Advisory Database

HAS_WEAKNESS (2)

[Weakness]Improper Access Control
[Weakness]Incorrect Authorization

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-5h2w-qmfp-ggp6 — Ninja Signal Threat Intelligence | Ninja Signal