Gateway plugin route auth protection for /api/channels could be bypassed using encoded dot-segment traversal (for example ..%2f) in path variants that plugin handlers normalize.
openclaw2026.2.25<= 2026.2.252026.2.26 (planned next release)Under affected versions, crafted alternate paths could bypass gateway auth checks for protected plugin channel routes when plugin handlers decode/canonicalize the incoming path and then route to /api/channels/... handlers.
258d615c45527ffda37cecd08cd268f97461bde0patched_versions is pre-set to the planned next release (2026.2.26). After npm publish, maintainers only need to publish the advisory.
OpenClaw thanks @zpbrent for reporting.
{
"cwe_ids": [
"CWE-22",
"CWE-289"
],
"github_reviewed_at": "2026-03-03T18:54:35Z",
"nvd_published_at": "2026-03-19T22:16:39Z",
"severity": "HIGH",
"github_reviewed": true
}