Description
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route that skips operator.read scope validation. Attackers can access session history without proper operator read permissions by sending HTTP requests to the vulnerable endpoint.
Problem types
CWE-863: Incorrect Authorization
Product status
Any version before 2026.3.25
2026.3.25 (semver)
Credits
Peng Zhou (@zpbrent)
References
github.com/...enclaw/security/advisories/GHSA-5jvj-hxmh-6h6j (GitHub Security Advisory (GHSA-5jvj-hxmh-6h6j))
github.com/...ommit/1c45123231516fa50f8cf8522ba5ff2fb2ca7aea (Patch Commit)
www.vulncheck.com/...on-bypass-in-http-session-history-route (VulnCheck Advisory: OpenClaw < 2026.3.25 - Authorization Bypass in HTTP Session History Route)