highCVSS 7.1Vulnerability

GHSA-vmhq-cqm9-6p7q

### Summary An authorization mismatch in the gateway let an authenticated caller with only `operator.write` use `browser.request` to reach browser profile management routes that persist configuration to disk. In practice, this exposed an admin-only configuration write primitive through `/profiles/create`. ### Impact A write-scoped operator could create or modify browser profiles and store attacker-chosen remote CDP endpoints without holding `operator.admin`. ### Affected versions `openclaw` `<= 2026.3.8` ### Patch Fixed in `openclaw` `2026.3.11` and included in later releases such as `2026.3.12`. Browser profile creation now requires the correct admin boundary, and regression tests cover the write-vs-admin authorization split.

Properties

ghsa_id
GHSA-vmhq-cqm9-6p7q
severity
high
summary
OpenClaw: `browser.request` let `operator.write` persist admin-only browser profile changes
cvss_score
7.1
cve_id
GHSA-vmhq-cqm9-6p7q
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
is_ghsa_only
true
ghsa_published
2026-03-13T20:54:25Z
source_url
https://github.com/advisories/GHSA-vmhq-cqm9-6p7q
ghsa_updated
2026-03-13T20:54:27Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph