{"id":"GHSA-6xg4-82hv-cp6f","summary":"OpenClaw: Gateway chat.send ACP-only provenance guard could be bypassed by client identity spoofing","details":"## Summary\n\nACP-only provenance fields in `chat.send` were gated by self-declared client metadata from the WebSocket handshake rather than verified authorization state.\n\n## Impact\n\nA normal authenticated operator client could spoof ACP identity labels and inject reserved provenance fields intended only for the ACP bridge.\n\n## Affected Component\n\n`src/gateway/server-methods/chat.ts, src/gateway/server/ws-connection/message-handler.ts`\n\n## Fixed Versions\n\n- Affected: `\u003c= 2026.3.24`\n- Patched: `\u003e= 2026.3.28`\n- Latest stable `2026.3.28` contains the fix.\n\n## Fix\n\nFixed by commit `4b9542716c` (`Gateway: require verified scope for chat provenance`).","aliases":["CVE-2026-41299"],"modified":"2026-04-21T00:11:25.118793Z","published":"2026-03-31T23:57:51Z","database_specific":{"github_reviewed_at":"2026-03-31T23:57:51Z","nvd_published_at":null,"cwe_ids":["CWE-290","CWE-807"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-6xg4-82hv-cp6f"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/commit/4b9542716c26ac77652bcaa0f562043b298b409f"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"}],"affected":[{"package":{"name":"openclaw","ecosystem":"npm","purl":"pkg:npm/openclaw"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2026.3.28"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2026.3.24","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6xg4-82hv-cp6f/GHSA-6xg4-82hv-cp6f.json"}}],"schema_version":"1.9.0"}