GHSA-hv93-r4j3-q65f

Suggest an improvement
Source
https://github.com/advisories/GHSA-hv93-r4j3-q65f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-hv93-r4j3-q65f/GHSA-hv93-r4j3-q65f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hv93-r4j3-q65f
Published
2026-02-17T16:43:34Z
Modified
2026-02-17T17:02:26Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N CVSS Calculator
Summary
OpenClaw Hook Session Key Override Enables Targeted Cross-Session Routing
Details

Summary

The issue is not deterministic session keys by itself. The exploitable path was accepting externally supplied sessionKey values on authenticated hook ingress, allowing a hook token holder to route messages into chosen sessions.

Affected Behavior

  • POST /hooks/agent accepted payload sessionKey and used it directly for session routing.
  • Common session-key shapes (for example agent:main:dm:<peerId>) were often derivable from known metadata, making targeted routing practical when request-level override was enabled.

Attack Preconditions

  • Attacker can call hook endpoints with a valid hook token.
  • Hook ingress allows request-selected sessionKey values.
  • Target session keys can be derived or guessed.

Without those preconditions, deterministic key formats alone do not provide access.

Impact

  • Integrity: targeted message/prompt injection into chosen sessions.
  • Persistence: poisoned context can affect subsequent turns when the same session key is reused.
  • Confidentiality impact is secondary and depends on additional weaknesses.

Affected Versions

  • openclaw >= 2.0.0-beta3 and < 2026.2.12

Patched Versions

  • openclaw >= 2026.2.12

Fix

OpenClaw now uses secure defaults for hook session routing:

  • POST /hooks/agent rejects payload sessionKey unless hooks.allowRequestSessionKey=true.
  • Added hooks.defaultSessionKey for fixed ingress routing.
  • Added hooks.allowedSessionKeyPrefixes to constrain explicit routing keys.
  • Security audit warns on unsafe hook session-routing settings.

Recommended Configuration

{
  "hooks": {
    "enabled": true,
    "token": "${OPENCLAW_HOOKS_TOKEN}",
    "defaultSessionKey": "hook:ingress",
    "allowRequestSessionKey": false,
    "allowedSessionKeyPrefixes": ["hook:"]
  }
}

Credit

Thanks @alpernae for responsible reporting.

Database specific
{
    "cwe_ids":  [
        "CWE-330",
        "CWE-639"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-17T16:43:34Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0-beta3
Fixed
2026.2.12

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-hv93-r4j3-q65f/GHSA-hv93-r4j3-q65f.json"