GHSA-943q-mwmv-hhvh
## Summary OpenClaw Gateway exposes an authenticated HTTP endpoint (`POST /tools/invoke`) intended for invoking a constrained set of tools. Two issues could combine to significantly increase blast radius in misconfigured or exposed deployments: - The HTTP gateway layer did not deny high-risk session orchestration tools by default, allowing a caller with Gateway auth to invoke tools like `sessions_spawn` / `sessions_send` and pivot into creating or controlling agent sessions. - ACP clients could auto-approve permission requests for risky tools with insufficient user interaction/guardrails, reducing the friction that should normally prevent silent execution or mutation. ## Impact If the Gateway is reachable by an attacker and they obtain a valid Gateway token, they may be able to: - Escalate from single-tool invocation to spawning/controlling sessions and reach command execution capabilities depending on tool policy and runtime environment. - Perform cross-session message injection via `sessions_send`. - In ACP-integrated scenarios, obtain unintended approvals for non-read/search tool permissions. ## CVSS - `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H` (8.8) ## Affected versions - `openclaw < 2026.2.14` ## Fixed in - `openclaw >= 2026.2.14` ## Remediation The default behavior is now hardened: - PR #15390: deny high-risk tools over HTTP `/tools/invoke` by default (with `gateway.tools.{allow,deny}` overrides) and harden ACP permission handling. - Commit `bb1c3dfe1`: ACP clients now prompt for any non-read/search permission request (fail closed for mutating/execution/fetch operations). - Commit `539689a2f`: security audit warns when `gateway.tools.allow` re-enables default-denied HTTP tools, since this can increase RCE blast radius if the Gateway is reachable. - Commit `153a7644e`: ACP safe-kind inference is stricter to avoid accidental auto-approval due to substring matches (still auto-approves only confident `read/search`). ## Mitigations / deployment g
Properties
- ghsa_id
- GHSA-943q-mwmv-hhvh
- severity
- high
- summary
- OpenClaw: Gateway /tools/invoke tool escalation + ACP permission auto-approval
- cvss_score
- 8.8
- cve_id
- GHSA-943q-mwmv-hhvh
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- is_ghsa_only
- true
- ghsa_published
- 2026-03-02T23:32:22Z
- source_url
- https://github.com/advisories/GHSA-943q-mwmv-hhvh
- ghsa_updated
- 2026-03-02T23:32:26Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph