highVulnerability

GHSA-jr6x-2q95-fh2g

### Summary An authorization mismatch allowed authenticated callers with `operator.write` access to invoke owner-only tool surfaces (`gateway`, `cron`) through `agent` runs in scoped-token deployments. ### Impact On affected deployments, write-scoped callers could perform control-plane actions beyond intended write scope. ### Fix Owner-only gating is now enforced consistently for owner-only tool surfaces during agent execution, and tool scope classification was tightened to remove the privilege mismatch. ### Affected and Patched Versions - Affected: `<= 2026.2.26` - Patched: `2026.3.1`

Properties

ghsa_id
GHSA-jr6x-2q95-fh2g
severity
high
summary
OpenClaw's authorization mismatch allowed write-scope agent runs to reach owner-only tools
cve_id
GHSA-jr6x-2q95-fh2g
is_ghsa_only
true
ghsa_published
2026-03-02T21:59:51Z
source_url
https://github.com/advisories/GHSA-jr6x-2q95-fh2g
ghsa_updated
2026-03-02T21:59:52Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Improper Privilege Management
[Weakness]Missing Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph