highVulnerability
GHSA-9p93-7j67-5pc2
## Summary Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding. ## Details The HTTP route previously treated any bearer-authenticated request as admin-eligible and could call without binding the action to requester ownership or caller-granted operator scopes. The flaw removes the bearer-token admin fallback and keeps remote session kills on the local-admin or requester-owned path only.
Properties
- ghsa_id
- GHSA-9p93-7j67-5pc2
- severity
- high
- summary
- OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding
- cve_id
- GHSA-9p93-7j67-5pc2
- is_ghsa_only
- true
- ghsa_published
- 2026-03-27T22:28:25Z
- source_url
- https://github.com/advisories/GHSA-9p93-7j67-5pc2
- ghsa_updated
- 2026-03-27T22:28:26Z
Related Entities (4)
AFFECTS (1)
→[Software]npm/OpenClaw
HAS_WEAKNESS (2)
→[Weakness]Sensitive Information in Resource Not Removed Before Reuse
→[Weakness]Incorrect Authorization
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph