Description
OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. Attackers can invoke owner-only behavior through the affected loopback path to execute restricted tools when the feature is enabled and reachable.
Problem types
Product status
Any version before 2026.4.24
2026.4.24 (semver)
Credits
zsx (@zsxsoft)
KeenSecurityLab
qclawer
qclawer
References
github.com/...enclaw/security/advisories/GHSA-rj6p-xmxr-qj4h (GitHub Security Advisory (GHSA-rj6p-xmxr-qj4h))
www.vulncheck.com/...nly-tool-policy-bypass-via-mcp-loopback