highVulnerability

GHSA-9p93-7j67-5pc2

## Summary Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding. ## Details The HTTP route previously treated any bearer-authenticated request as admin-eligible and could call without binding the action to requester ownership or caller-granted operator scopes. The flaw removes the bearer-token admin fallback and keeps remote session kills on the local-admin or requester-owned path only.

Properties

ghsa_id
GHSA-9p93-7j67-5pc2
severity
high
summary
OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding
cve_id
GHSA-9p93-7j67-5pc2
is_ghsa_only
true
ghsa_published
2026-03-27T22:28:25Z
source_url
https://github.com/advisories/GHSA-9p93-7j67-5pc2
ghsa_updated
2026-03-27T22:28:26Z

Related Entities (4)

AFFECTS (1)

→[Software]npm/OpenClaw

HAS_WEAKNESS (2)

→[Weakness]Sensitive Information in Resource Not Removed Before Reuse
→[Weakness]Incorrect Authorization

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-9p93-7j67-5pc2 — Ninja Signal Threat Intelligence | Ninja Signal