GHSA-vmhq-cqm9-6p7q
### Summary An authorization mismatch in the gateway let an authenticated caller with only `operator.write` use `browser.request` to reach browser profile management routes that persist configuration to disk. In practice, this exposed an admin-only configuration write primitive through `/profiles/create`. ### Impact A write-scoped operator could create or modify browser profiles and store attacker-chosen remote CDP endpoints without holding `operator.admin`. ### Affected versions `openclaw` `<= 2026.3.8` ### Patch Fixed in `openclaw` `2026.3.11` and included in later releases such as `2026.3.12`. Browser profile creation now requires the correct admin boundary, and regression tests cover the write-vs-admin authorization split.
Properties
- ghsa_id
- GHSA-vmhq-cqm9-6p7q
- severity
- high
- summary
- OpenClaw: `browser.request` let `operator.write` persist admin-only browser profile changes
- cvss_score
- 7.1
- cve_id
- GHSA-vmhq-cqm9-6p7q
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
- is_ghsa_only
- true
- ghsa_published
- 2026-03-13T20:54:25Z
- source_url
- https://github.com/advisories/GHSA-vmhq-cqm9-6p7q
- ghsa_updated
- 2026-03-13T20:54:27Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph