mediumVulnerability

GHSA-8m9v-xpgf-g99m

### Summary Unauthorized senders could trigger two command paths without sender authorization checks: 1. stop-like natural-language abort triggers 2. `/models` command output ### Impact An unauthorized sender could disrupt active sessions and view model/auth metadata that should be authorization-gated. ### Fix Sender authorization is now enforced for stop-like abort triggers and `/models` listings. ### Affected and Patched Versions - Affected: `<= 2026.2.26` - Patched: `2026.3.1`

Properties

ghsa_id
GHSA-8m9v-xpgf-g99m
severity
medium
summary
OpenClaw has an unauthorized sender bypass in its stop triggers and /models command authorization
cve_id
GHSA-8m9v-xpgf-g99m
is_ghsa_only
true
ghsa_published
2026-03-02T21:54:30Z
source_url
https://github.com/advisories/GHSA-8m9v-xpgf-g99m
ghsa_updated
2026-03-02T21:54:30Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph