GHSA-f6h3-846h-2r8w
### Summary In certain elevated-mode configurations, `tools.elevated.allowFrom` accepted broader identity signals than intended. The fix tightens matching to sender-scoped identity by default and makes mutable metadata matching explicit. ### Context OpenClaw is commonly used in 1:1 chats or trusted group chats. In that intended model, this issue is best treated as authorization hardening / defense-in-depth for elevated sender approval. ### Affected Packages / Versions - Package: `openclaw` (npm) - Latest published npm version at triage: `2026.2.21-2` - Affected versions: `<= 2026.2.21-2` - Planned patched version (pre-set for publish-ready advisory): `2026.2.22` ### Details Elevated sender authorization now matches sender-scoped identity values only by default (`SenderId`, `From`, `SenderE164`) and no longer considers recipient routing fields such as `ctx.To`. Mutable sender metadata (`SenderName`, `SenderUsername`, `SenderTag`) now requires explicit allowlist prefixes (`name:`, `username:`, `tag:`). Explicit identity prefixes are also supported (`id:`, `from:`, `e164:`). ### Fix Commit(s) - `6817c0ec7b4fa830123d4f5c340f075a4bd04ee2` ### Release Process Note The advisory `patched_versions` is pre-set to the planned next release (`2026.2.22`). Once npm `[email protected]` is published, this advisory can be published without additional content edits. OpenClaw thanks @jiseoung for reporting.
Properties
- ghsa_id
- GHSA-f6h3-846h-2r8w
- severity
- medium
- summary
- OpenClaw's elevated allowFrom accepted broader identity signals than specified within sender-scoped authorization
- cve_id
- GHSA-f6h3-846h-2r8w
- is_ghsa_only
- true
- ghsa_published
- 2026-03-04T18:58:07Z
- source_url
- https://github.com/advisories/GHSA-f6h3-846h-2r8w
- ghsa_updated
- 2026-03-04T18:58:10Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph