Unauthorized senders could trigger two command paths without sender authorization checks:
1. stop-like natural-language abort triggers
2. /models command output
An unauthorized sender could disrupt active sessions and view model/auth metadata that should be authorization-gated.
Sender authorization is now enforced for stop-like abort triggers and /models listings.
<= 2026.2.262026.3.1| Base score | Version | Severity | Vector |
|---|---|---|---|
| 6.9 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-8m9v-xpgf-g99m ↗ |
| CWE id | Name |
|---|---|
| CWE-863 | Incorrect Authorization |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| npm | openclaw | < 2026.3.1 | 2026.3.1 | — |