
Cloud Vulnerability DB
A community-led vulnerabilities database
Fixed in OpenClaw 2026.3.24, the current shipping release. Title
Non-owner command-authorized sender can change the owner-only/sendsession delivery policy CWE
CWE-285 Improper Authorization CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Base score: 5.4 (Medium) Severity Assessment
Medium. This is a real owner-only authorization bypass, but the demonstrated impact is limited to persistent mutation of the current session’s delivery policy rather than direct code execution, sandbox escape, or cross-host compromise. Impact
A non-owner sender who is allowed to run commands can invoke/send on|off|inheritand persistently change the current session’ssendPolicy, even though OpenClaw documents/sendas owner-only. That lets a lower-trust participant:
/send off), suppressing future replies in that chat;/send on) after the owner intentionally disabled it;/send inherit).
Affected Componentv2026.3.23 (ccfeecb6887cd97937e33a71877ad512741e82b2), published 2026-03-23T23:15:50Z.
Exact vulnerable path on the shipped tag:src/auto-reply/reply/commands-session.ts:212-239handleSendPolicyCommand(...) checks only params.command.isAuthorizedSender.params.sessionEntry.sendPolicy and persists the session entry.
Authorization behavior that makes this reachable:src/auto-reply/command-auth.ts:401-407senderIsOwner is computed separately from general command authorization.src/auto-reply/command-auth.ts:420-429senderIsOwner === false.src/auto-reply/command-auth.owner-default.test.ts:10-47docs/tools/slash-commands.md:112/send on|off|inherit is documented as owner-only.docs/concepts/session-tool.md:156sendPolicy is documented as settable via sessions.patch or owner-only /send on|off|inherit.
Related privilege model:src/gateway/method-scopes.ts:131-133sessions.patch is admin-scoped, which reinforces that session-delivery-policy mutation is treated as privileged state.
Version history:ea018a68ccb92dbc735bc1df9880d5c95c63ca35 (refactor(auto-reply): split reply pipeline).v2026.1.14-1v2026.3.23
Technical Reproductionv2026.3.23.commands.allowFrom;commands.ownerAllowFrom.sessionEntry and sessionStore./send off as the non-owner but command-authorized sender.isAuthorizedSender === truesenderIsOwner === falsesessionEntry.sendPolicy, and persists the session entry.
Demonstrated Impactsrc/auto-reply/reply/commands-session.ts:232-238/send inherit deletes sessionEntry.sendPolicysessionEntry.sendPolicy = sendPolicyCommand.modepersistSessionEntry(params)
The mutation is not gated by owner status, only by general command authorization.
That changes subsequent delivery behavior for the current session, which matches the documented meaning of sendPolicy.
Environmentv2026.3.23ccfeecb6887cd97937e33a71877ad512741e82b22026-03-23T23:15:50Z2026-03-24
Duplicate Check/send.
This is distinct from:GHSA-r7vr-gr74-94p8/config and /debug, not /send.
This is the same authorization class, but a different privileged command surface that still lacks the owner check.
In Scope CheckSECURITY.md because:SECURITY.md:151-152 explicitly says non-owner sender status matters for owner-only tools and commands;/send is explicitly documented as owner-only, so this is a direct owner-only authorization bypass, not a complaint about normal shared-agent steering.
This is therefore a concrete authorization flaw against a documented product boundary.
Remediation Advice/send to require owner status, not just command authorization./config, /debug, and owner-only /plugins writes./send must still be rejected unless senderIsOwner === true./send on|off|inherit normally.Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."