OpenClaw Gateway exposes an authenticated HTTP endpoint (POST /tools/invoke) intended for invoking a constrained set of tools. Two issues could combine to significantly increase blast radius in misconfigured or exposed deployments:
sessions_spawn / sessions_send and pivot into creating or controlling agent sessions.If the Gateway is reachable by an attacker and they obtain a valid Gateway token, they may be able to:
sessions_send.CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (8.8)openclaw < 2026.2.14openclaw >= 2026.2.14The default behavior is now hardened:
/tools/invoke by default (with gateway.tools.{allow,deny} overrides) and harden ACP permission handling.bb1c3dfe1: ACP clients now prompt for any non-read/search permission request (fail closed for mutating/execution/fetch operations).539689a2f: security audit warns when gateway.tools.allow re-enables default-denied HTTP tools, since this can increase RCE blast radius if the Gateway is reachable.153a7644e: ACP safe-kind inference is stricter to avoid accidental auto-approval due to substring matches (still auto-approves only confident read/search).gateway.bind="loopback" / openclaw gateway run --bind loopback.gateway.tools.allow) as high-risk and audit such configurations carefully.OpenClaw thanks @aether-ai-agent for reporting this issue and contributing remediation work.
{
"cwe_ids": [
"CWE-78"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-02T23:32:22Z",
"nvd_published_at": null,
"severity": "HIGH"
}