OpenClaw Session Visibility Bypass Vulnerability in Unsandboxed Invocations
Vulnerability
A session visibility bypass vulnerability has been identified in OpenClaw versions prior to 2026.3.31. The issue arises in the session_status function, which fails to apply the configured visibility restrictions for unsandboxed invocations. This allows attackers to bypass session-policy controls and access restricted session information.
Impact
Exploitation of this vulnerability allows for unauthorized access to restricted session information, bypassing established session-policy controls.
Reproduction
To reproduce this vulnerability, invoke the session_status function in an unsandboxed context. The absence of sandbox constraints will allow the function to bypass the visibility restrictions configured in the session-policy, granting access to restricted session information.
Remediation
Users can upgrade to OpenClaw version 2026.3.31 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
