GHSA-6fvr-66p3-3qj4

Suggest an improvement
Source
https://github.com/advisories/GHSA-6fvr-66p3-3qj4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6fvr-66p3-3qj4/GHSA-6fvr-66p3-3qj4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6fvr-66p3-3qj4
Aliases
Published
2026-07-02T16:05:03Z
Modified
2026-07-02T16:26:33Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
Details

Summary

OpenClaw hook ingress can start automated agent runs using a configured hook token. In affected releases, a hook-triggered run could select a bundled CLI backend that received owner-scoped MCP loopback authority instead of a scope appropriate for hook ingress.

This issue affects the boundary between hook-token automation and owner-only MCP tools. It does not affect deployments with hooks disabled.

Affected configurations

This affects deployments where hooks are enabled, /hooks/agent is reachable with a valid hook token, and a bundled CLI backend can be selected for the hook-triggered run.

Impact

A caller with the hook token could cause the spawned CLI runtime to see or call MCP tools that should have been owner-only. The practical impact depends on which MCP tools are available; the reported proof used persistent cron state as a representative owner-only action.

Patched Versions

The first stable patched version is 2026.5.20.

Fixed in the 2026.5.20 stable release.

Mitigations

Upgrade to openclaw@2026.5.20 or later. Keep hook tokens secret, restrict network access to hook endpoints, and disable hooks when they are not needed.

Database specific
{
    "cwe_ids":  [
        "CWE-200",
        "CWE-266",
        "CWE-284"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-02T16:05:03Z",
    "nvd_published_at":  "2026-06-11T21:16:23Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.5.20

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6fvr-66p3-3qj4/GHSA-6fvr-66p3-3qj4.json"