{"id":"GHSA-q2qc-744p-66r2","summary":"OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility","details":"## Summary\n\n`session_status` sessionId resolution bypasses sandboxed session-tree visibility\n\n## Affected Packages / Versions\n\n- Package: `openclaw`\n- Affected versions: `\u003e= 2026.3.11, \u003c= 2026.3.24`\n- First patched version: `2026.3.25`\n- Latest published npm version at verification time: `2026.3.24`\n\n## Details\n\n`session_status` previously resolved a `sessionId` to a canonical session key after early visibility checks, letting sandboxed children reach parent or sibling sessions that were blocked by explicit `sessionKey`. Commit `d9810811b6c3c9266d7580f00574e5e02f7663de` enforces visibility after `sessionId` resolution so sandboxed callers cannot escape their session tree.\n\nVerified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `d9810811b6c3c9266d7580f00574e5e02f7663de`.\n\n## Fix Commit(s)\n\n- `d9810811b6c3c9266d7580f00574e5e02f7663de`","aliases":["CVE-2026-35636"],"modified":"2026-07-08T08:26:45.891122991Z","published":"2026-03-29T15:47:50Z","database_specific":{"cwe_ids":["CWE-639","CWE-863"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-29T15:47:50Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-q2qc-744p-66r2"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/commit/d9810811b6c3c9266d7580f00574e5e02f7663de"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"}],"affected":[{"package":{"name":"openclaw","ecosystem":"npm","purl":"pkg:npm/openclaw"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2026.3.11"},{"fixed":"2026.3.28"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2026.3.24","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-q2qc-744p-66r2/GHSA-q2qc-744p-66r2.json"}}],"schema_version":"1.9.0"}