Description
OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assume operator identity and potentially escalate privileges.
Problem types
Authentication Bypass by Spoofing
Product status
Any version before 2026.5.18
2026.5.18 (semver)
Credits
cantinagen
Ellahi (@Ellahinator)
References
github.com/...enclaw/security/advisories/GHSA-rggc-m335-3wvj (GitHub Security Advisory (GHSA-rggc-m335-3wvj))
www.vulncheck.com/...forgery-via-trusted-proxy-configuration (VulnCheck Advisory: OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration)