/phone arm//phone disarm Bypasses operator.admin Scope Check for External Channels
openclaw (npm)2026.3.31<=2026.3.24>= 2026.3.28v2026.3.28aa66ae1fc797d3298cc409ed2c5da69a89950a45 — 2026-03-27T20:35:42Z2026.3.28.Thanks @AntAISecurityLab for reporting.
{
"github_reviewed": true,
"github_reviewed_at": "2026-04-07T18:10:04Z",
"cwe_ids": [
"CWE-285"
],
"severity": "MODERATE",
"nvd_published_at": null
}