lowCVSS 4.2Vulnerability

GHSA-p3pv-c954-9m6f

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-c28g-vh7m-fm7v. This link is maintained to preserve external references. ### Original Description OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner senders to execute owner-enforced slash commands when wildcard inbound senders are configured without explicit owner allowFrom settings. Attackers can exploit this by sending commands like /send, /config, or /debug on affected channels to bypass owner-only command authorization checks.

Properties

ghsa_id
GHSA-p3pv-c954-9m6f
summary
Duplicate Advisory: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners
severity
low
cvss_score
4.2
cve_id
GHSA-p3pv-c954-9m6f
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-05-11T18:31:46Z
source_url
https://github.com/advisories/GHSA-p3pv-c954-9m6f
ghsa_updated
2026-05-18T15:30:47Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/OpenClaw

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-p3pv-c954-9m6f (CVSS 4.2) — Ninja Signal Threat Intelligence | Ninja Signal