This advisory has been withdrawn because it is a duplicate of GHSA-r6xh-pqhr-v4xh. This link is maintained to preserve external references.
OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present themselves as owner to bypass owner-gated operations by manipulating the sender-owner header metadata.
{
"github_reviewed": true,
"severity": "HIGH",
"nvd_published_at": "2026-05-06T20:16:35Z",
"cwe_ids": [
"CWE-290"
],
"github_reviewed_at": "2026-05-11T16:12:46Z"
}