Description
OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag to default to true. Non-owner voice participants can exploit this omission to access owner-only tools including gateway and cron functionality in mixed-trust channels.
Problem types
CWE-863: Incorrect Authorization
Product status
Any version before 2026.3.2
2026.3.2 (semver)
Credits
tdjackey
References
github.com/...enclaw/security/advisories/GHSA-wpg9-4g4v-f9rc (GitHub Security Advisory (GHSA-wpg9-4g4v-f9rc))
www.vulncheck.com/...ion-in-discord-voice-transcript-handler (VulnCheck Advisory: OpenClaw < 2026.3.2 - Missing Owner Flag Validation in Discord Voice Transcript Handler)