highVulnerability

GHSA-6xg4-82hv-cp6f

## Summary ACP-only provenance fields in `chat.send` were gated by self-declared client metadata from the WebSocket handshake rather than verified authorization state. ## Impact A normal authenticated operator client could spoof ACP identity labels and inject reserved provenance fields intended only for the ACP bridge. ## Affected Component `src/gateway/server-methods/chat.ts, src/gateway/server/ws-connection/message-handler.ts` ## Fixed Versions - Affected: `<= 2026.3.24` - Patched: `>= 2026.3.28` - Latest stable `2026.3.28` contains the fix. ## Fix Fixed by commit `4b9542716c` (`Gateway: require verified scope for chat provenance`).

Properties

ghsa_id
GHSA-6xg4-82hv-cp6f
summary
OpenClaw: Gateway chat.send ACP-only provenance guard could be bypassed by client identity spoofing
severity
high
cve_id
GHSA-6xg4-82hv-cp6f
is_ghsa_only
true
ghsa_published
2026-03-31T23:57:51Z
source_url
https://github.com/advisories/GHSA-6xg4-82hv-cp6f
ghsa_updated
2026-03-31T23:57:51Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

REPORTED_BY (1)

[Source]GitHub Advisory Database

HAS_WEAKNESS (2)

[Weakness]Authentication Bypass by Spoofing
[Weakness]Reliance on Untrusted Inputs in a Security Decision

Explore deeper with Ninja Signal's threat intelligence graph