highCVSS 8.8Vulnerability

GHSA-r7vr-gr74-94p8

### Summary OpenClaw documented `/config` and `/debug` as owner-only commands, but the command handlers checked only whether the sender was command-authorized. A lower-trust sender who was intentionally allowed to run commands could still reach privileged configuration and debugging surfaces. ### Impact This allowed a non-owner sender to read or change privileged configuration that should have remained restricted to owners. ### Affected versions `openclaw` `<= 2026.3.11` ### Patch Fixed in `openclaw` `2026.3.12`. Owner checks are now enforced for privileged command surfaces, and regression tests cover `/config` and `/debug` access control.

Properties

ghsa_id
GHSA-r7vr-gr74-94p8
severity
high
summary
OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces
cvss_score
8.8
cve_id
GHSA-r7vr-gr74-94p8
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-03-13T20:55:09Z
source_url
https://github.com/advisories/GHSA-r7vr-gr74-94p8
ghsa_updated
2026-03-13T20:55:11Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Improper Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-r7vr-gr74-94p8 (CVSS 8.8) — Ninja Signal Threat Intelligence | Ninja Signal