OpenClaw Scope Bypass Vulnerability in Gateway Chat Route

Vulnerability

A scope bypass vulnerability has been identified in OpenClaw versions prior to 2026.5.18. This vulnerability exists in the Gateway 'chat.send' route, allowing scoped clients to execute privileged commands. Attackers with 'operator.write' scope can send commands through inherited external routes, bypassing the 'operator.approvals' and 'operator.admin' scope requirements. This exploitation enables unauthorized modifications to plugins, configurations, MCP, allowlists, and ACP.

Impact

Exploitation of this vulnerability allows commands that should require 'operator.approvals' or 'operator.admin' to be executed with only 'operator.write' privileges. This bypass could lead to unauthorized changes in administrative areas such as plugins, configurations, and allowlists.

Remediation

Users are advised to upgrade to OpenClaw version 2026.5.18 or later. Before upgrading, it is recommended to avoid granting 'operator.write' tokens to clients that can send commands into sessions with external routes, unless those clients are trusted with administrative command effects.

Added: May 29, 2026, 4:26 PM
Updated: May 29, 2026, 4:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.8
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.