{"id":"GHSA-8m9v-xpgf-g99m","summary":"OpenClaw has an unauthorized sender bypass in its stop triggers and /models command authorization","details":"### Summary\nUnauthorized senders could trigger two command paths without sender authorization checks:\n1. stop-like natural-language abort triggers\n2. `/models` command output\n\n### Impact\nAn unauthorized sender could disrupt active sessions and view model/auth metadata that should be authorization-gated.\n\n### Fix\nSender authorization is now enforced for stop-like abort triggers and `/models` listings.\n\n### Affected and Patched Versions\n- Affected: `\u003c= 2026.2.26`\n- Patched: `2026.3.1`","modified":"2026-03-04T15:13:55.006071Z","published":"2026-03-02T21:54:30Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-863"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-02T21:54:30Z"},"references":[{"type":"WEB","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-8m9v-xpgf-g99m"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"}],"affected":[{"package":{"name":"openclaw","ecosystem":"npm","purl":"pkg:npm/openclaw"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2026.3.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-8m9v-xpgf-g99m/GHSA-8m9v-xpgf-g99m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}