GHSA-jf6w-m8jw-jfxc
## Summary In affected versions of `openclaw`, a gateway caller with `operator.write` could issue `agent` requests containing `/new` or `/reset` and reach the same reset path used by the admin-only `sessions.reset` RPC. ## Impact On gateways where a caller is intentionally granted `operator.write` but not `operator.admin`, that caller could reset targeted conversation state through `agent` slash commands. This crosses the documented method-scope boundary between write-scoped messaging and admin-only session mutation. ## Affected Packages and Versions - Package: `openclaw` (npm) - Affected versions: `<= 2026.3.8` - Fixed in: `2026.3.11` ## Technical Details Scope checks were enforced only on the outer RPC method. The `agent` slash-command path reused admin-only reset logic internally, so a write-scoped caller could reach session-reset mutation without holding `operator.admin`. ## Fix OpenClaw no longer routes conversation `/new` and `/reset` through the admin-only `sessions.reset` entry point. Reset logic now lives in a shared service, while `sessions.reset` remains admin-only. The fix shipped in `[email protected]`. ## Workarounds Upgrade to `2026.3.11` or later.
Properties
- ghsa_id
- GHSA-jf6w-m8jw-jfxc
- severity
- medium
- summary
- OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`
- cvss_score
- 6.1
- cve_id
- GHSA-jf6w-m8jw-jfxc
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
- is_ghsa_only
- true
- ghsa_published
- 2026-03-13T15:48:11Z
- source_url
- https://github.com/advisories/GHSA-jf6w-m8jw-jfxc
- ghsa_updated
- 2026-03-13T15:48:12Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph