
Cloud Vulnerability DB
A community-led vulnerabilities database
Inter-session messages sent via sessions_send could be interpreted as direct end-user instructions because they were persisted as role: "user" without provenance metadata.
openclaw (npm)<= 2026.2.12 (i.e. < 2026.2.13)2026.2.13 (patched versions >= 2026.2.13)A delegated or internal session could inject instructions into another session that appeared equivalent to externally-originated user input.
This is an instruction-provenance confusion issue (confused-deputy style), which can lead to unintended privileged behavior in workflows that trust role: "user" as a sole authority signal.
Before the fix, routed inter-session prompts were stored as regular user turns without a verifiable source marker. As a result, downstream workers and transcript readers could not distinguish:
OpenClaw now carries explicit input provenance end-to-end for routed prompts. Key changes:
inputProvenance) with kind values including inter_session.sessions_send and agent-to-agent steps now set inter-session provenance when invoking target runs.message.provenance.kind = "inter_session" (role remains user for provider compatibility).[Inter-session message]) for clearer model-side disambiguation.85409e401b6586f83954cb53552395d7aab04797If immediate upgrade is not possible:
sessions_send in affected environments.Reported by @anbecker. Thanks @anbecker for reporting.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."