GHSA-hw9r-h9mr-4jff: OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
Some internal command handlers require operator.approvals or operator.admin scopes. In affected releases, a scoped Gateway chat.send request delivered through an inherited external route could be evaluated as an external-channel command while still carrying the lower Gateway client scopes.
This issue affects scoped Gateway clients. It does not apply to shared-secret bearer HTTP compatibility endpoints, which are documented as full operator surfaces under OpenClaw’s trust model.
References
Code Behaviors & Features
Detect and mitigate GHSA-hw9r-h9mr-4jff with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →