OpenClaw Session Visibility Bypass Vulnerability in Unsandboxed Invocations

Vulnerability

A session visibility bypass vulnerability has been identified in OpenClaw versions prior to 2026.3.31. The issue arises in the session_status function, which fails to apply the configured visibility restrictions for unsandboxed invocations. This allows attackers to bypass session-policy controls and access restricted session information.

Impact

Exploitation of this vulnerability allows for unauthorized access to restricted session information, bypassing established session-policy controls.

Reproduction

To reproduce this vulnerability, invoke the session_status function in an unsandboxed context. The absence of sandbox constraints will allow the function to bypass the visibility restrictions configured in the session-policy, granting access to restricted session information.

Remediation

Users can upgrade to OpenClaw version 2026.3.31 or later to address this vulnerability.

Added: Apr 23, 2026, 10:29 PM
Updated: Apr 23, 2026, 10:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
0.0
relevance
6.5
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.