ACP child sessions inherit subagent security envelope constraints.
A restricted subagent spawning an ACP child session could fail to carry forward subagent-only constraints such as depth, child-count limits, control scope, or target-agent restrictions.
ACP spawn now resolves and persists child subagent envelope fields, enforces maximum depth and active-child caps, and applies the inherited control scope to child ACP sessions.
OpenClaw thanks @zsxsoft, @qclawer, and @KeenSecurityLab for reporting.
{
"cwe_ids": [
"CWE-277"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-04T20:21:49Z",
"nvd_published_at": null,
"severity": "MODERATE"
}